Description
WordPress is prone to an unauthorized access vulnerability. Successfully exploiting this issue will allow attackers to reset the password of arbitrary accounts. WordPress 2.6.1 is vulnerable; prior versions may also be affected.
Remediation
Update to WordPress version 2.6.2 or latest
References
http://www.suspekt.org/2008/08/18/mysql-and-sql-column-truncation-vulnerabilities/
http://www.exploit-db.com/exploits/6397/
http://www.exploit-db.com/exploits/6421/
http://packetstormsecurity.org/files/view/69821/wordpress261-admin.txt
Related Vulnerabilities
Oracle JRE CVE-2018-2618 Vulnerability (CVE-2018-2618)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6610)
Ruby on Rails Improper Input Validation Vulnerability (CVE-2013-3221)
WordPress Plugin MaxBlogPress Max Banner Ads Cross-Site Scripting (1.9)
Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2021-33334)