CVE-2011-4673: SQL Injection
Published Dec 2, 2011
·Updated
SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
Affected Software
2 affected components
Automattic Jetpack
WordPress
Event History
Dec 2, 2011
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
06:55 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-4673?
CVE-2011-4673 is considered a critical severity vulnerability due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2011-4673?
To fix CVE-2011-4673, update the Jetpack plugin for WordPress to the latest secure version released by Automattic.
3
Who is affected by CVE-2011-4673?
Users of the Jetpack plugin for WordPress, particularly those using affected versions, are at risk from CVE-2011-4673.
4
What type of vulnerability is CVE-2011-4673?
CVE-2011-4673 is classified as an SQL injection vulnerability.
5
Can CVE-2011-4673 be exploited remotely?
Yes, CVE-2011-4673 can be exploited remotely by attackers to execute arbitrary SQL commands.