Main Website RSS FeedCurrent Article

Wordpress HTML Injection Vulnerability

Wow .. i just got back .. and i read a very interesting news about the recent wordpress html injection vulnerability issue that is exists on several .. um .. almost all versions of wordpress below 2.0.6 (well i dont know anything about the 1.x series of wordpress because i never use it before)

Fortunately there is already a fix for this problem and you can do it by applying the latest patch from Wordpress Trac into the templates.php file in your wp-admin directory

As as a note, if you want to see a proof of concept regarding this wordpress issue, you can go to David Kierznowski homepage and see it by yourself

And yet another note, Wordpress 2.0.6 RC2 has been released (from the WP-Testers Mailing Lists) and this new release candidate already include a fix for this problem

RSS Feed for This Post1 Comment(s)

  1. 1
    jameswillisisthebest | Sep 9, 2007 at 3:47 / 3:47 AM | Links to this comments | Reply

    This is my first post
    just saying HI

2 Trackback(s)

  1. From bunnie’s blog » Blog Archive » pwned | Jan 11, 2007
  2. From bunnie’s blog » Blog Archive » pwned | Jan 11, 2007

RSS Feed for This PostPost a Comment

Line and paragraph breaks automatic, e-mail address never displayed, avoid using spammy words or phrases to prevent your comment from going into the oblivion, HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>