Title : WordPress "user_login" Column SQL Truncation Vulnerability VUPEN ID : VUPEN/ADV-2008-2553 CVE ID : CVE-2008-4106 - CVE-2008-4107 CWE ID : CWE-331
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-09-15
Technical Description
A vulnerability has been identified in WordPress, which could be exploited by attackers to gain knowledge of sensitive information. This issue is caused due to predictable passwords being randomly generated when the PRNG is freshly seeded and output of the PRNG is leaked to the user, which could allow attackers to potentially disclose the administrator's automatically generated password.