Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2011-4899


wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is appropriate, which allows remote attackers to configure an arbitrary database via the dbhost and dbname parameters, and subsequently conduct static code injection and cross-site scripting (XSS) attacks via (1) an HTTP request or (2) a MySQL query. NOTE: the vendor disputes the significance of this issue; however, remote code execution makes the issue important in many realistic environments


Published

2012-01-30T17:55:00.750

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application wordpress wordpress ≤ 3.3.1 Yes
Application wordpress wordpress 0.7 Yes
Application wordpress wordpress 0.71 Yes
Application wordpress wordpress 0.72 Yes
Application wordpress wordpress 0.711 Yes
Application wordpress wordpress 1.0 Yes
Application wordpress wordpress 1.0.1 Yes
Application wordpress wordpress 1.0.2 Yes
Application wordpress wordpress 1.2 Yes
Application wordpress wordpress 1.2.1 Yes
Application wordpress wordpress 1.2.2 Yes
Application wordpress wordpress 1.5 Yes
Application wordpress wordpress 1.5.1 Yes
Application wordpress wordpress 1.5.1.2 Yes
Application wordpress wordpress 1.5.1.3 Yes
Application wordpress wordpress 1.5.2 Yes
Application wordpress wordpress 2.0 Yes
Application wordpress wordpress 2.0.1 Yes
Application wordpress wordpress 2.0.2 Yes
Application wordpress wordpress 2.0.3 Yes
Application wordpress wordpress 2.0.4 Yes
Application wordpress wordpress 2.0.5 Yes
Application wordpress wordpress 2.0.6 Yes
Application wordpress wordpress 2.0.7 Yes
Application wordpress wordpress 2.0.8 Yes
Application wordpress wordpress 2.0.9 Yes
Application wordpress wordpress 2.0.10 Yes
Application wordpress wordpress 2.0.11 Yes
Application wordpress wordpress 2.1 Yes
Application wordpress wordpress 2.1.1 Yes
Application wordpress wordpress 2.1.2 Yes
Application wordpress wordpress 2.1.3 Yes
Application wordpress wordpress 2.2 Yes
Application wordpress wordpress 2.2.1 Yes
Application wordpress wordpress 2.2.2 Yes
Application wordpress wordpress 2.2.3 Yes
Application wordpress wordpress 2.3 Yes
Application wordpress wordpress 2.3.1 Yes
Application wordpress wordpress 2.3.2 Yes
Application wordpress wordpress 2.3.3 Yes
Application wordpress wordpress 2.5 Yes
Application wordpress wordpress 2.5.1 Yes
Application wordpress wordpress 2.6 Yes
Application wordpress wordpress 2.6.1 Yes
Application wordpress wordpress 2.6.2 Yes
Application wordpress wordpress 2.6.3 Yes
Application wordpress wordpress 2.6.5 Yes
Application wordpress wordpress 2.7 Yes
Application wordpress wordpress 2.7.1 Yes
Application wordpress wordpress 2.8 Yes
Application wordpress wordpress 2.8.1 Yes
Application wordpress wordpress 2.8.2 Yes
Application wordpress wordpress 2.8.3 Yes
Application wordpress wordpress 2.8.4 Yes
Application wordpress wordpress 2.8.5 Yes
Application wordpress wordpress 2.8.6 Yes
Application wordpress wordpress 2.9 Yes
Application wordpress wordpress 2.9.1 Yes
Application wordpress wordpress 2.9.2 Yes
Application wordpress wordpress 3.0 Yes
Application wordpress wordpress 3.0.1 Yes
Application wordpress wordpress 3.0.2 Yes
Application wordpress wordpress 3.0.3 Yes
Application wordpress wordpress 3.0.4 Yes
Application wordpress wordpress 3.0.5 Yes
Application wordpress wordpress 3.0.6 Yes
Application wordpress wordpress 3.1 Yes
Application wordpress wordpress 3.1.1 Yes
Application wordpress wordpress 3.1.2 Yes
Application wordpress wordpress 3.1.3 Yes
Application wordpress wordpress 3.1.4 Yes
Application wordpress wordpress 3.2.1 Yes
Application wordpress wordpress 3.3 Yes

References