CVE-2003-1598
Publication date 1 October 2014
Last updated 24 July 2024
Ubuntu priority
Description
WordPress 0.7 (b2 cafelog code) allows SQL injection. / Blog.header.php. $ posts not converted to an integer, so we can inject sql in this variable. In MySQL 4.x can use UNION and subselects to obtain privileges.