Go Back   Website Hosting - VPS Hosting - Domain Registration Ireland :: Blacknight > Technical Support > Security Notices

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 30-06-05, 10:54 AM
Junior Member
 
Join Date: May 2004
Posts: 18
Default Wordpress Multiple Vulnerabilities

1) Input passed to the "comment" and "p" parameters in "post.php" isn't properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in an administrator's browser session in context of an affected site.

2) Some input passed via the XML-RPC interface isn't properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

3) Input passed to the "message" parameter in "wp-login.php" isn't properly verified before it is used. This can be exploited to manipulate the message content of the mail sent via the "Forgotten Password" feature.

Successful exploitation requires that "register_globals" is enabled.

4) An input validation error in the administration section can be exploited to inject arbitrary PHP code into existing plugins.

Successful exploitation requires administrative privileges.

It is also possible to disclose the full path to certain scripts by accessing them with invalid input.

The vulnerabilities have been reported in version 1.5.1.2 and prior.

Solution:
Update to version 1.5.1.3.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Tags
multiple, vulnerabilities, wordpress

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Wordpress User Security Issue blacknight Security Notices 1 16-01-07 09:30 AM
phpAdsNew Multiple Vulnerabilities niall Security Notices 0 17-08-05 03:36 PM
WordPress "cache_lastpostdate" PHP Code Insertion niall Security Notices 0 12-08-05 09:34 AM
Drupal PHP Code Execution Vulnerabilities niall Security Notices 0 30-06-05 11:00 AM
Xoops Cross-Site Scripting and SQL Injection Vulnerabilities niall Security Notices 0 30-06-05 10:55 AM


All times are GMT. The time now is 10:43 PM.


VPS Hosting Web Hosting Ireland Blacknight Blog Blacknight Status

Powered by: vBulletin Version 3.7.3, Copyright ©2000 - 2009, Jelsoft Enterprises Limited.
Blacknight 2005 - 2008 | VPS Hosting

SEO by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17