wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external MySQL database servers, which allows remote attackers to use WordPress as a proxy for brute-force attacks or denial of service attacks via the dbhost parameter, a different vulnerability than CVE-2011-4898. NOTE: the vendor disputes the significance of this issue because an incomplete WordPress installation might be present on the network for only a short time
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2012-01-30T17:00:00Z
Updated: 2024-09-16T18:39:54.478Z
Reserved: 2012-01-30T00:00:00Z
Link: CVE-2012-0937
Vulnrichment
No data.
NVD
Status : Modified
Published: 2012-01-30T17:55:01.330
Modified: 2024-11-21T01:36:00.460
Link: CVE-2012-0937
Redhat
No data.