, its free!




Vulnerability Found in WordPress

WordPress XSS Vulnerability 2.06 updateA XSS vulnerability has been in found in wp-admin/template.php which could allow malicious web users to inject arbitary web scripts or HTML code through the file parameter.

This exploit could allow remote attackers to do nasty things by injecting php or html codes into your wordpress core files.

Vulnerable versions of Wordpress:

  • Wordpress (B2) 0.6.2 .1
  • Wordpress (B2) 0.6.2
  • WordPress 2.0.5
  • WordPress 2.0.4
  • WordPress 2.0.3
  • WordPress 2.0.2
  • WordPress 2.0.1
  • WordPress 2.0
  • WordPress 1.5.2
  • WordPress 1.5.1 .3
  • WordPress 1.5.1 .2
  • WordPress 1.5.1
  • WordPress 1.5
  • WordPress 1.2.2
  • WordPress 1.2.1
  • WordPress 1.2
  • WordPress 0.71
  • WordPress 0.7

Only the latest WordPress WordPress 2.0.6 is not vulnerable to this.

To go about patching the vulnerability, you will need to download the patched templates.php and then replace it with your exiting wp-admin/templates.php file.

To learn more about this vulnerability, visit Operation N or Security Focus.
Report via Tech-Buzz.

Popularity: 7% [?]

Sphere: Related Content

Spread the word: Del.icio.us it   Digg it   Submit to Reddit   Submit to Blinklist   Add to Netscape   Furl it   Sphere: Related Content Help Yourself:   RSS comments   RSS posts   trackback trackback

One Response to “Vulnerability Found in WordPress”

  1. Phalgun Says:

    Nice post.
    Would you like to exchange links in blogroll ?

Leave a Reply


Comments

RSS
  • splitsplut: Aaah, games, they’ve taken so much of my precious lifetime already. I...
  • Razvan: Hey guyz i really need to get the themes made by Rod McFarland can any1 send...
  • Jp: Forgot to mention.. I did use the workaround Nick advised first and used it to...
  • Jp: o.k. not sure if this forum is still live but I have found a way to get your data...
  • jp: Same situation as xdaiio J god - can you post the solution you found...
  • his mate: ive used this same .reg hack before and it works perfect but this just...
  • adam gardner: This isn’t a “linux version” It’s some dope-ass...

Chicklets

RSS