PDA

View Full Version : Wordpress user_login Column SQL Truncation Vulnerability



newsbot
15-09-2008, 11:06 PM
MySQL column truncation allows resetting the passwords of wordpress users to random strings. Combined with weaknesses in PHP's PRNG this allows determining the admin password.

-</p>

Make your website safer. Use an external vulnerability scanner (http://www.beyondsecurity.com/vulnerability-scanner.html). Nothing to install, zero maintenance!</p>

http://www.securiteam.com/unixfocus/5YP0D1FPFO.html