CVE-2007-4154SQL Injection in Wordpress

4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.8%
top 25.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 3
Latest updateMay 1

Description

SQL injection vulnerability in options.php in WordPress 2.2.1 allows remote authenticated administrators to execute arbitrary SQL commands via the page_options parameter to (1) options-general.php, (2) options-writing.php, (3) options-reading.php, (4) options-discussion.php, (5) options-privacy.php, (6) options-permalink.php, (7) options-misc.php, and possibly other unspecified components.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/wordpress< wordpress 2.2.2-1 (bookworm)
Debianwordpress/wordpress< 2.2.2-1+3

🔴Vulnerability Details

2
GHSA
GHSA-jhw4-989v-7prf: SQL injection vulnerability in options2022-05-01
OSV
CVE-2007-4154: SQL injection vulnerability in options2007-08-03

📋Vendor Advisories

1
Debian
CVE-2007-4154: wordpress - SQL injection vulnerability in options.php in WordPress 2.2.1 allows remote auth...2007
CVE-2007-4154 — SQL Injection in Debian Wordpress | cvebase