Unrated severityNVD Advisory· Published Sep 18, 2008· Updated Apr 23, 2026
CVE-2008-4106
CVE-2008-4106
Description
WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user's password to a random value by registering a similar username and then requesting a password reset, related to a "SQL column truncation vulnerability." NOTE: the attacker can discover the random password by also exploiting CVE-2008-4107.
Affected products
34cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*+ 33 more
- cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*range: <=2.6.1
- cpe:2.3:a:wordpress:wordpress:0.71-gold:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.0.1-miles:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.0.2-blakey:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.0-platinum:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.2-delta:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.2-mingus:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.5.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.5.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.5.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.5-strayhorn:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.5:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
17- wordpress.org/development/2008/09/wordpress-262/nvdPatch
- secunia.com/advisories/31870nvdVendor Advisory
- marc.infonvd
- secunia.com/advisories/31737nvd
- securityreason.com/securityalert/4272nvd
- securitytracker.com/idnvd
- www.debian.org/security/2009/dsa-1871nvd
- www.openwall.com/lists/oss-security/2008/09/11/6nvd
- www.securityfocus.com/archive/1/496287/100/0/threadednvd
- www.securityfocus.com/bid/31068nvd
- www.sektioneins.de/advisories/SE-2008-05.txtnvd
- www.suspekt.org/2008/08/18/mysql-and-sql-column-truncation-vulnerabilities/nvd
- www.vupen.com/english/advisories/2008/2553nvd
- www.exploit-db.com/exploits/6397nvd
- www.exploit-db.com/exploits/6421nvd
- www.redhat.com/archives/fedora-package-announce/2008-September/msg00607.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2008-September/msg00629.htmlnvd
News mentions
0No linked articles in our index yet.