CVE-2008-4106

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
18/09/2008
Last modified:
11/10/2018

Description

WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user's password to a random value by registering a similar username and then requesting a password reset, related to a "SQL column truncation vulnerability." NOTE: the attacker can discover the random password by also exploiting CVE-2008-4107.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 2.6.1 (including)
cpe:2.3:a:wordpress:wordpress:0.71-gold:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.0-platinum:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.0.1-miles:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.0.2-blakey:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2-delta:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2-mingus:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.5-strayhorn:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.5.1.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.5.1.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0:*:*:*:*:*:*:*