Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 192347 - <www-apps/wordpress-2.2.3 Script Insertion and SQL Injection Vulnerabilities
Summary: <www-apps/wordpress-2.2.3 Script Insertion and SQL Injection Vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial
Assignee: Gentoo Security
URL: http://secunia.com/advisories/26771/
Whiteboard: ~3 [noglsa]
Keywords:
: 192409 (view as bug list)
Depends on:
Blocks:
 
Reported: 2007-09-12 20:14 UTC by Tobias Heinlein (RETIRED)
Modified: 2007-10-04 09:37 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tobias Heinlein (RETIRED) gentoo-dev 2007-09-12 20:14:51 UTC
Some vulnerabilities have been reported in Wordpress, which can be exploited by malicious users to conduct script insertion attacks and by malicious people to conduct SQL injection attacks.

1) The "unfiltered_html" privilege feature can be bypassed by adding a field named "no_filter". This can be exploited by malicious users without the "unfiltered_html" privilege to e.g. post blog entries with arbitrary HTML and script code via specially crafted POST requests.

2) Input passed to certain parameters (e.g. the "post_type" parameter of the URL passed to the "pingback.extensions.getPingbacks()" XMLRPC method) is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

The vulnerabilities are reported in Wordpress prior to 2.2.3 and Wordpress MU prior to 1.2.5a.

Solution:
Update to Wordpress version 2.2.3 or Wordpress MU version 1.2.5a.
Comment 1 Tobias Heinlein (RETIRED) gentoo-dev 2007-09-12 20:25:28 UTC
Oops, rbu just told me that 2.2.3 is already in the tree.
Closing with regards to bug 168529.
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2007-09-13 11:48:59 UTC
*** Bug 192409 has been marked as a duplicate of this bug. ***
Comment 3 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-10-04 09:36:11 UTC
the portage tree used to contain a vulnerable version of wordpress...
Comment 4 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-10-04 09:37:09 UTC
(In reply to comment #3)
> the portage tree used to contain a vulnerable version of wordpress...
> 

... and fixed.

Closing with [noglsa] because wordpress is p.masked