Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress 'Wp-trackback.PHP' SQL注入漏洞
Vulnerability Description
当输入数据包含一个数字参数时,WordPress 2.0.6及之前版本中的wp-trackback.php没有正确的打乱变量,这使得远程攻击者可以借助tb_id参数,执行任意的SQL指令。
CVSS Information
N/A
Vulnerability Type
N/A