Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2011-4898

wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether providing intentionally vague error messages during installation would be reasonable from a usability perspective

  • Published: Jan 30, 2012
  • Updated: Nov 8, 2023
  • CVE: CVE-2011-4898
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:N/A:P

CWEs:

Software From Fixed in
WordPress / wordpress 3.0.5 3.0.5.x
WordPress / wordpress 2.0.11 2.0.11.x
WordPress / wordpress 2.8.6 2.8.6.x
WordPress / wordpress 2.0 2.0.x
WordPress / wordpress 2.1.1 2.1.1.x
WordPress / wordpress 2.2.3 2.2.3.x
WordPress / wordpress 2.0.2 2.0.2.x
WordPress / wordpress 2.1 2.1.x
WordPress / wordpress 2.0.6 2.0.6.x
WordPress / wordpress 2.0.1 2.0.1.x
WordPress / wordpress 2.8.4 2.8.4.x
WordPress / wordpress 2.0.4 2.0.4.x
WordPress / wordpress 3.0.2 3.0.2.x
WordPress / wordpress 3.2.1 3.2.1.x
WordPress / wordpress 0.711 0.711.x
WordPress / wordpress 3.1.4 3.1.4.x
WordPress / wordpress 2.2 2.2.x
WordPress / wordpress 1.2.1 1.2.1.x
WordPress / wordpress 0.7 0.7.x
WordPress / wordpress 2.1.3 2.1.3.x
WordPress / wordpress 3.0 3.0.x
WordPress / wordpress 2.8 2.8.x
WordPress / wordpress 2.0.7 2.0.7.x
WordPress / wordpress 2.1.2 2.1.2.x
WordPress / wordpress 3.0.1 3.0.1.x
WordPress / wordpress 2.7.1 2.7.1.x
WordPress / wordpress 0.71 0.71.x
WordPress / wordpress 2.6.3 2.6.3.x
WordPress / wordpress 2.0.5 2.0.5.x
WordPress / wordpress 2.8.3 2.8.3.x
WordPress / wordpress 2.6.5 2.6.5.x
WordPress / wordpress 3.1.3 3.1.3.x
WordPress / wordpress 2.2.2 2.2.2.x
WordPress / wordpress 2.3.3 2.3.3.x
WordPress / wordpress 2.0.9 2.0.9.x
WordPress / wordpress 2.8.1 2.8.1.x
WordPress / wordpress 2.2.1 2.2.1.x
WordPress / wordpress 2.7 2.7.x
WordPress / wordpress 1.5.2 1.5.2.x
WordPress / wordpress - 3.3.1.x
WordPress / wordpress 1.0.1 1.0.1.x
WordPress / wordpress 0.72 0.72.x
WordPress / wordpress 3.0.4 3.0.4.x
WordPress / wordpress 2.6.2 2.6.2.x
WordPress / wordpress 2.9 2.9.x
WordPress / wordpress 3.1 3.1.x
WordPress / wordpress 2.3.1 2.3.1.x
WordPress / wordpress 1.0.2 1.0.2.x
WordPress / wordpress 2.5.1 2.5.1.x
WordPress / wordpress 2.0.3 2.0.3.x
WordPress / wordpress 2.6.1 2.6.1.x
WordPress / wordpress 1.5.1.2 1.5.1.2.x
WordPress / wordpress 3.1.2 3.1.2.x
WordPress / wordpress 1.2 1.2.x
WordPress / wordpress 3.0.6 3.0.6.x
WordPress / wordpress 2.9.2 2.9.2.x
WordPress / wordpress 2.5 2.5.x
WordPress / wordpress 3.1.1 3.1.1.x
WordPress / wordpress 1.2.2 1.2.2.x
WordPress / wordpress 2.0.10 2.0.10.x
WordPress / wordpress 2.9.1 2.9.1.x
WordPress / wordpress 1.0 1.0.x
WordPress / wordpress 3.3 3.3.x
WordPress / wordpress 1.5 1.5.x
WordPress / wordpress 2.8.2 2.8.2.x
WordPress / wordpress 1.5.1 1.5.1.x
WordPress / wordpress 3.0.3 3.0.3.x
WordPress / wordpress 1.5.1.3 1.5.1.3.x
WordPress / wordpress 2.3.2 2.3.2.x
WordPress / wordpress 2.6 2.6.x
WordPress / wordpress 2.8.5 2.8.5.x
WordPress / wordpress 2.0.8 2.0.8.x
WordPress / wordpress 2.3 2.3.x