Alarming WordPress Security Vulnerabilities
beNi released 3 alarming vulnerabilities in the popular WordPress blog platform
- Cross Site Scripting – it didn’t work for me
- Forced Redirect – it worked for me
- Directory Traversal – n /a
Due to the really huge install base, I really hope that the folks at wordpress.org issue a patch quickly to address these vulnerabilities. Update : It sems that the site hosting the proof of concept exploits is down for maintenance.(thanks leion)
Thank you for reading this post. You can now Read Comment (1) or Leave A Trackback.
Print This Post
Post Info
This entry was posted on Sunday, February 11th, 2007 . Tagged with:You can follow any responses to this entry through the Comments Feed. You can Leave A Comment, or A Trackback.
Previous Post: How to Turn Firefox Into an Attack Webserver »
Next Post: Here is the definitive fix for Universal PDF XSS Vulnerability »
Read More
Related Reading:
Latest Posts:
- SC Magazine 2010 Awards Winners
- Qualys Unveils 3 New Services – Some Are FREE!
- OWASP Broken Web Applications – Excelent Learning Tool
- GFI WebMonitor 2009 Review
- ModSecurity 2.5 – New Book Soon To Be Released
- NetWitness releases NextGen version 9.0
- Twitter Weekly Updates for 2009-07-19
- Twitter Weekly Updates for 2009-07-12
- Twitter Weekly Updates for 2009-07-05
- Twitter Weekly Updates for 2009-06-28




February 17th, 2007 01:27
All the links gave 404 error..