CVE-2012-2109: SQL Injection
Published Sep 4, 2012
·Updated
SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attackers to execute arbitrary SQL commands via the page parameter in an activitywidgetfilter action.
Affected Software
7 affected components
BuddyPress BuddyPress=1.5
BuddyPress BuddyPress=1.5.1
BuddyPress BuddyPress=1.5.2
BuddyPress BuddyPress=1.5.3
BuddyPress BuddyPress=1.5.3.1
BuddyPress BuddyPress=1.5.4
WordPress WordPress
Remediation
Patch Available
Event History
Sep 4, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2109?
CVE-2012-2109 is categorized as a critical SQL injection vulnerability that can lead to arbitrary SQL command execution.
2
How do I fix CVE-2012-2109?
To fix CVE-2012-2109, upgrade the BuddyPress plugin to version 1.5.5 or later.
3
What versions of BuddyPress are affected by CVE-2012-2109?
CVE-2012-2109 affects BuddyPress versions 1.5.x prior to 1.5.5.
4
Can CVE-2012-2109 be exploited remotely?
Yes, CVE-2012-2109 can be exploited by remote attackers to execute unauthorized SQL commands.
5
What is the impact of exploiting CVE-2012-2109?
Exploiting CVE-2012-2109 can lead to data breaches and potential manipulation of the database.