Summary
The remote host is missing an update to wordpress
announced via advisory DSA 1564-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201564-1
Insight
Several remote vulnerabilities have been discovered in wordpress, a weblog manager. The Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2007-3639
Insufficient input sanitising allowed for remote attackers to redirect visitors to external websites.
CVE-2007-4153
Multiple cross-site scripting vulnerabilities allowed remote authenticated administrators to inject arbitrary web script or HTML.
CVE-2007-4154
SQL injection vulnerability allowed allowed remote authenticated administrators to execute arbitrary SQL commands.
CVE-2007-0540
WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.
[no CVE name yet]
Insufficient input sanitising caused an attacker with a normal user account to access the administrative interface.
For the stable distribution (etch), these problems have been fixed in version 2.0.10-1etch2.
For the unstable distribution (sid), these problems have been fixed in version 2.2.3-1.
We recommend that you upgrade your wordpress package.
Severity
Classification
-
CVE CVE-2007-0540, CVE-2007-3639, CVE-2007-4153, CVE-2007-4154 -
CVSS Base Score: 6.5
AV:N/AC:L/Au:S/C:P/I:P/A:P
Related Vulnerabilities