Release date: 2012-09-04
Updated on:
Affected Systems:
WordPress Buddypress 1.5.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2012-2109
WordPress is a Blog (Blog, Blog) engine developed using the PHP language and MySQL database. you can create your own Blog on servers that support PHP and MySQL databases.
The WordPress BuddyPress plug-in earlier than version 1.5.x has the SQL Injection Vulnerability. The page parameter operated by activity_widget_filter allows remote attackers to execute arbitrary SQL commands.
<* Source: Ivan Terkin
Link: http://www.exploit-db.com/exploits/18690/
Http://osvdb.org/show/osvdb/80763
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://wordpress.org/