Add to Google Reader, Bloglines, Netvibes

You are browsing comments for Wordpress template.php Exploit Discovered. To add your own comment, please click here.

Pages: « 1 [2] 3 »

  1. Thanks boy! I just researched a bit and patched it up.

  2. [...] TechBuzz lists all WordPress versions that are in danger of this exploit, but the short story is unless you’re using 2.0.6 you’re not safe. And as far as I know that one hasn’t been released officially yet. It’s advised you patch the culprit file in the meantime. (Make sure to back those files up first!) * It’s so popular, in fact, that sneaky people are making money off of hinting at how you can use it to make your money. They obviously haven’t head of WP’s support community. [...]

  3. Thx for highlighting me.I had been notifying other bloggers about it.

  4. Just wanted to add one more thing.I had a contact with Matt(Wordpress) on email , He confimred about the news.So its safe.You can get to read about the email on my blog.

  5. [...] Tech Buzz lists the vulnerable versions (almost all versions prior to 2.06), and adds, A Cross-site scripting (XSS) vulnerability has been in found in wp-admin/template.php which could allow malicious web users to inject arbitary web scripts or HTML code through the file parameter. [...]

  6. [...] Bekannt ist diese Lücke wohl schon seit dem 27. Dezember, wie man bei dem Entdecker (?) Operation n nachlesen kann. techbuzz listet alle betroffenen stabilen Wordpress-Versionen. [...]

  7. Thanks for the heads up on this potential problem.

Pages: « 1 [2] 3 »

Leave a Reply

Grab our RSS feed.

Updates straight to your inbox.