First published: Thu Jul 06 2006(Updated: )
index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an invalid paged parameter, which displays the information in an SQL error message. NOTE: this issue has been disputed by a third party who states that the issue does not leak any target-specific information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | =2.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3389 is considered a medium severity vulnerability due to its potential for information disclosure.
To fix CVE-2006-3389, upgrade your WordPress installation to a version later than 2.0.3.
CVE-2006-3389 can leak sensitive information such as SQL table prefixes through error messages.
CVE-2006-3389 specifically affects WordPress version 2.0.3.
Yes, CVE-2006-3389 has been disputed by a third party claiming it does not result in sensitive information leakage.