Wordpress Vulnerability

A command execution vulnerability has been found in WordPress’s handling of incoming cookie information which allows remote attackers to cause the program to execute arbitrary code if the PHP settings of register_globals has been set to On.

Already a perl and php exploit is available. It affects WordPress version 1.5.1.3 and before when register_globals is set to On. The information has been provided by Kartoffelguru.

WordPress developers are working on a fix.

[Source: Simple Thoughts]

Sphere: Related Content

Posted on August 13, 2005
75 words · print

Comments are closed.

Leave a reply

Name (required)

Email (required)

Website

Comments

If this is your first time commenting on Slobokan's Site O' Schtuff, your comment will be held for moderation. Once your comment is approved by Slobokan, any future comments will not be held for moderation. Comments may be edited or deleted at the discretion of Slobokan, and may be re-produced at any time for the purpose of discussion, argument, or ridicule. This policy is not open for debate. If you do not agree, do not comment. It's that simple.