<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Wordpress template.php Exploit Discovered</title>
	<atom:link href="http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/feed/" rel="self" type="application/rss+xml" />
	<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/</link>
	<description>Tech News, Web and Geeky Stuff!</description>
	<lastBuildDate>Wed, 17 Mar 2010 05:35:46 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Internet Marketing Campus &#187; Archive &#187; Script Updates And Keeping Your Site Hacker Safe</title>
		<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/comment-page-1/#comment-81670</link>
		<dc:creator>Internet Marketing Campus &#187; Archive &#187; Script Updates And Keeping Your Site Hacker Safe</dc:creator>
		<pubDate>Fri, 18 May 2007 11:56:40 +0000</pubDate>
		<guid isPermaLink="false">http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/#comment-81670</guid>
		<description>[...] WordPress template.php Exploit Discovered [...]</description>
		<content:encoded><![CDATA[<p>[...] WordPress template.php Exploit Discovered [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/comment-page-1/#comment-28345</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Thu, 11 Jan 2007 15:28:57 +0000</pubDate>
		<guid isPermaLink="false">http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/#comment-28345</guid>
		<description>Thanks for the heads up on this potential problem.</description>
		<content:encoded><![CDATA[<p>Thanks for the heads up on this potential problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eine gute und eine schlechte Neuigkeit zu Wordpress &#8212; Software Guide</title>
		<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/comment-page-1/#comment-26524</link>
		<dc:creator>Eine gute und eine schlechte Neuigkeit zu Wordpress &#8212; Software Guide</dc:creator>
		<pubDate>Thu, 04 Jan 2007 22:19:11 +0000</pubDate>
		<guid isPermaLink="false">http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/#comment-26524</guid>
		<description>[...] Bekannt ist diese LÃ¼cke wohl schon seit dem 27. Dezember, wie man bei dem Entdecker (?) Operation n nachlesen kann. techbuzz listet alle betroffenen stabilen Wordpress-Versionen. [...]</description>
		<content:encoded><![CDATA[<p>[...] Bekannt ist diese LÃ¼cke wohl schon seit dem 27. Dezember, wie man bei dem Entdecker (?) Operation n nachlesen kann. techbuzz listet alle betroffenen stabilen Wordpress-Versionen. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Cross Site Scripting Vulnerability in templates.php Uncovered at The Blog Herald</title>
		<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/comment-page-1/#comment-26409</link>
		<dc:creator>WordPress Cross Site Scripting Vulnerability in templates.php Uncovered at The Blog Herald</dc:creator>
		<pubDate>Thu, 04 Jan 2007 13:27:41 +0000</pubDate>
		<guid isPermaLink="false">http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/#comment-26409</guid>
		<description>[...] Tech Buzz lists the vulnerable versions (almost all versions prior to 2.06), and adds, A Cross-site scripting (XSS) vulnerability has been in found in wp-admin/template.php which could allow malicious web users to inject arbitary web scripts or HTML code through the file parameter. [...]</description>
		<content:encoded><![CDATA[<p>[...] Tech Buzz lists the vulnerable versions (almost all versions prior to 2.06), and adds, A Cross-site scripting (XSS) vulnerability has been in found in wp-admin/template.php which could allow malicious web users to inject arbitary web scripts or HTML code through the file parameter. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ashish Mohta</title>
		<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/comment-page-1/#comment-26307</link>
		<dc:creator>Ashish Mohta</dc:creator>
		<pubDate>Wed, 03 Jan 2007 18:23:08 +0000</pubDate>
		<guid isPermaLink="false">http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/#comment-26307</guid>
		<description>Just wanted to add one more thing.I had a contact with Matt(Wordpress) on email , He confimred about the news.So its safe.You can get to read about the email on my blog.</description>
		<content:encoded><![CDATA[<p>Just wanted to add one more thing.I had a contact with Matt(Wordpress) on email , He confimred about the news.So its safe.You can get to read about the email on my blog.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ashish Mohta</title>
		<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/comment-page-1/#comment-26305</link>
		<dc:creator>Ashish Mohta</dc:creator>
		<pubDate>Wed, 03 Jan 2007 18:13:03 +0000</pubDate>
		<guid isPermaLink="false">http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/#comment-26305</guid>
		<description>Thx for highlighting me.I had been notifying other bloggers about it.</description>
		<content:encoded><![CDATA[<p>Thx for highlighting me.I had been notifying other bloggers about it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lovedeep Wadhwa</title>
		<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/comment-page-1/#comment-26256</link>
		<dc:creator>Lovedeep Wadhwa</dc:creator>
		<pubDate>Wed, 03 Jan 2007 13:49:32 +0000</pubDate>
		<guid isPermaLink="false">http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/#comment-26256</guid>
		<description>thanks for the update :shock:</description>
		<content:encoded><![CDATA[<p>thanks for the update <img src='http://tech-buzz.net/wp-includes/images/smilies/icon_eek.gif' alt=':shock:' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress XSS vulnerability in template.php * Stellify</title>
		<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/comment-page-1/#comment-26240</link>
		<dc:creator>WordPress XSS vulnerability in template.php * Stellify</dc:creator>
		<pubDate>Wed, 03 Jan 2007 11:34:57 +0000</pubDate>
		<guid isPermaLink="false">http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/#comment-26240</guid>
		<description>[...] TechBuzz lists all WordPress versions that are in danger of this exploit, but the short story is unless you&#8217;re using 2.0.6 you&#8217;re not safe. And as far as I know that one hasn&#8217;t been released officially yet. It&#8217;s advised you patch the culprit file in the meantime. (Make sure to back those files up first!)  * It&#8217;s so popular, in fact, that sneaky people are making money off of hinting at how you can use it to make your money. They obviously haven&#8217;t head of WP&#8217;s support community. [...]</description>
		<content:encoded><![CDATA[<p>[...] TechBuzz lists all WordPress versions that are in danger of this exploit, but the short story is unless you&#8217;re using 2.0.6 you&#8217;re not safe. And as far as I know that one hasn&#8217;t been released officially yet. It&#8217;s advised you patch the culprit file in the meantime. (Make sure to back those files up first!)  * It&#8217;s so popular, in fact, that sneaky people are making money off of hinting at how you can use it to make your money. They obviously haven&#8217;t head of WP&#8217;s support community. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vyoma</title>
		<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/comment-page-1/#comment-26195</link>
		<dc:creator>Vyoma</dc:creator>
		<pubDate>Wed, 03 Jan 2007 04:23:09 +0000</pubDate>
		<guid isPermaLink="false">http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/#comment-26195</guid>
		<description>Thanks boy!  I just researched a bit and patched it up.</description>
		<content:encoded><![CDATA[<p>Thanks boy!  I just researched a bit and patched it up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ajay</title>
		<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/comment-page-1/#comment-26192</link>
		<dc:creator>Ajay</dc:creator>
		<pubDate>Wed, 03 Jan 2007 03:41:42 +0000</pubDate>
		<guid isPermaLink="false">http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/#comment-26192</guid>
		<description>You mean existing... not exiting ;)</description>
		<content:encoded><![CDATA[<p>You mean existing&#8230; not exiting <img src='http://tech-buzz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Perfect Blogger</title>
		<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/comment-page-1/#comment-26173</link>
		<dc:creator>Perfect Blogger</dc:creator>
		<pubDate>Wed, 03 Jan 2007 01:12:32 +0000</pubDate>
		<guid isPermaLink="false">http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/#comment-26173</guid>
		<description>&lt;strong&gt;Security Alert: templates.php XSS vulnerability in WordPress&lt;/strong&gt;

Thanks to Thilak of TechBuzz, I&#8217;ve just learned about wp-admin/templates.php (part of your WordPress administration functionality) seems to be vulnerable to a rather nasty XSS exploit.

...</description>
		<content:encoded><![CDATA[<p><strong>Security Alert: templates.php XSS vulnerability in WordPress</strong></p>
<p>Thanks to Thilak of TechBuzz, I&#8217;ve just learned about wp-admin/templates.php (part of your WordPress administration functionality) seems to be vulnerable to a rather nasty XSS exploit.</p>
<p>&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zealios[dot]Net &#187; Blog Archive &#187; Wordpress Exploit.</title>
		<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/comment-page-1/#comment-26172</link>
		<dc:creator>Zealios[dot]Net &#187; Blog Archive &#187; Wordpress Exploit.</dc:creator>
		<pubDate>Wed, 03 Jan 2007 01:07:44 +0000</pubDate>
		<guid isPermaLink="false">http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/#comment-26172</guid>
		<description>[...] Thanks to Tech-Buzz. [...]</description>
		<content:encoded><![CDATA[<p>[...] Thanks to Tech-Buzz. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Garry Conn</title>
		<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/comment-page-1/#comment-26169</link>
		<dc:creator>Garry Conn</dc:creator>
		<pubDate>Wed, 03 Jan 2007 00:09:46 +0000</pubDate>
		<guid isPermaLink="false">http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/#comment-26169</guid>
		<description>Thilak,

What concerns me the most is that Wordpress.org hasn&#039;t released anything about this yet. There isn&#039;t anything posted on their blog and no official fixes. What more do you know about this and do you think that Wordpress.org knows about this?</description>
		<content:encoded><![CDATA[<p>Thilak,</p>
<p>What concerns me the most is that Wordpress.org hasn&#8217;t released anything about this yet. There isn&#8217;t anything posted on their blog and no official fixes. What more do you know about this and do you think that Wordpress.org knows about this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thilak</title>
		<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/comment-page-1/#comment-26147</link>
		<dc:creator>Thilak</dc:creator>
		<pubDate>Tue, 02 Jan 2007 19:50:17 +0000</pubDate>
		<guid isPermaLink="false">http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/#comment-26147</guid>
		<description>Rishi: No, there won&#039;t be a problem unless you are spotted by some attacker</description>
		<content:encoded><![CDATA[<p>Rishi: No, there won&#8217;t be a problem unless you are spotted by some attacker</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TechnoBeta Blog</title>
		<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/comment-page-1/#comment-26137</link>
		<dc:creator>TechnoBeta Blog</dc:creator>
		<pubDate>Tue, 02 Jan 2007 17:36:22 +0000</pubDate>
		<guid isPermaLink="false">http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/#comment-26137</guid>
		<description>[...] To learn more about this vulnerability, visit Operation N or Security Focus. Report via Tech-Buzz. [...]</description>
		<content:encoded><![CDATA[<p>[...] To learn more about this vulnerability, visit Operation N or Security Focus. Report via Tech-Buzz. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rishi</title>
		<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/comment-page-1/#comment-26136</link>
		<dc:creator>Rishi</dc:creator>
		<pubDate>Tue, 02 Jan 2007 17:36:14 +0000</pubDate>
		<guid isPermaLink="false">http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/#comment-26136</guid>
		<description>Thanks for the update!

Is there any problem if we didnt replace the file?</description>
		<content:encoded><![CDATA[<p>Thanks for the update!</p>
<p>Is there any problem if we didnt replace the file?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Phalgun</title>
		<link>http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/comment-page-1/#comment-26125</link>
		<dc:creator>Phalgun</dc:creator>
		<pubDate>Tue, 02 Jan 2007 16:35:03 +0000</pubDate>
		<guid isPermaLink="false">http://tech-buzz.net/2007/01/02/wordpress-templatephp-exploit-discovered/#comment-26125</guid>
		<description>Thanks &lt;strong&gt;Thilak&lt;/strong&gt; to add my name.</description>
		<content:encoded><![CDATA[<p>Thanks <strong>Thilak</strong> to add my name.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
