Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an invalid paged parameter, which displays the information in an SQL error message. NOTE: this issue has been disputed by a third party who states that the issue does not leak any target-specific information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress错误paged参数SQL操作信息泄露漏洞
Vulnerability Description
WordPress是一款免费的论坛Blog系统。 WordPress对错误请求的处理上存在漏洞,远程攻击者可能利用此漏洞获取服务器返回的包含SQL操作命令的敏感信息,可能有助于其进一步攻击。 如果攻击者向index.php传送了无效的paged参数的话,WordPress在返回的错误信息中会泄漏执行当前操作失败时的SQL命令,其中包含数据库表名前缀等敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A