WordPress Security Alert
Posted: Thu Sep 13, 2007 4:04 pm
[SA26771] Wordpress Script Insertion and SQL Injection Vulnerabilities
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2007-09-12
Some vulnerabilities have been reported in Wordpress, which can be
exploited by malicious users to conduct script insertion attacks and by
malicious people to conduct SQL injection attacks.
A malicious user could bypass the "unfiltered_html" privilege feature
by adding a field named "no_filter". This can be exploited to, for
example, post blog entries with arbitrary content by using specially
crafted POST requests.
A malicious person could manipulate SQL queries by injecting arbitrary
SQL code to certain parameters (for example, the "post_type"
parameter of the URL passed to the
"pingback.extensions.getPingbacks()" XMLRPC method), which are not
properly sanitised.
Wordpress has released version 2.2.3, and MU version 1.2.5a., which
solve these vulnerabilities. For more information, refer to the Full Advisory:
[url=\"http://secunia.com/advisories/26771/\"]http://secunia.com/advisories/26771/[/url]
Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2007-09-12
Some vulnerabilities have been reported in Wordpress, which can be
exploited by malicious users to conduct script insertion attacks and by
malicious people to conduct SQL injection attacks.
A malicious user could bypass the "unfiltered_html" privilege feature
by adding a field named "no_filter". This can be exploited to, for
example, post blog entries with arbitrary content by using specially
crafted POST requests.
A malicious person could manipulate SQL queries by injecting arbitrary
SQL code to certain parameters (for example, the "post_type"
parameter of the URL passed to the
"pingback.extensions.getPingbacks()" XMLRPC method), which are not
properly sanitised.
Wordpress has released version 2.2.3, and MU version 1.2.5a., which
solve these vulnerabilities. For more information, refer to the Full Advisory:
[url=\"http://secunia.com/advisories/26771/\"]http://secunia.com/advisories/26771/[/url]