A Wordpress HTML Exploit discovered, please patch it now!

advertisement logo

 

Security focus has published information regarding Wordpress HTML Injection Vulnerability which may allow attackers to inject PHP code straight into your Wordpress blog.

This can lead the attackers do nasty things such as deleting your post, defacing your blog, dropping your entire post (read: delete all your post !) and other dangerous attack. This particular vulnerability affects all Wordpress release from 1.2.1 to 2.0.5, Wordpress 2.0.6 (currently in RC2) is not affected by this vulnerability.

Wordpress bloggers are advised to apply patch released from Wordpress team in order to secure their blog from malicious users.

Applying the patch is simple, all you need to do is download the zip archive from Wordpress Trac, unzip it and upload wp-admin folder to your Wordpress host, overwriting the old template.php file.

Thanks to Faizi for blogging about this.

[Source]

Tags: , , , , , , ,

Bookmark this article
  • digg
  • YahooMyWeb
  • NewsVine
  • Netvouz
  • Reddit
  • Spurl
  • Furl
  • del.icio.us
  • StumbleUpon
  • Technorati
  • TwitThis

Keep updated with this website! : Subscribe to your email

Recommended Reading

9 smashing comments for this post.

  1. Infobulles.ch - Cours d'informatique - Formation informatique - Création et hébergement de site web - Genève - Suisse Said:

    village-idiot.org — wordpress 2.0.5 vulnerability http://www.village-idiot.org/archives/2007/01/02/wordpress-205-vulnerability/ A Wordpress HTML Exploit discovered, please patch it now! : mypapit gnu/linux blog http://blog.mypapit.net/2007/01/a-wordpress-html-exploit-discovered-please-patch-it-now.html WordPress “file” Script Insertion Vulnerability – Advisories – Secunia http://secunia.com/advisories/23587/ Changeset 4665 – WordPress Trac – Trac http://trac.wordpress.org/changeset/4665 Et n’oublez pas de surveiller celui-ci

  2. ping.sg :: The Community Meta Blog for Singapore Bloggers Said:

    into your Wordpress blog. This can lead the attackers do nasty things such as deleting your post, defacing your blog, dropping your entire post (read: delete all your post !) and other dangerous attack. This particular vulnerability … 1 pong [IMG Direct link]

  3. 1kHz Said:

    Thanks for the info papit. I’ve applied the patch.

  4. wordpress exploit: Web Search Results from Answers.com Said:

    [...] this means is… if you haven't …www.linickx.com/archives/279/ wordpress-exploit-on-milw0rmA Wordpress HTML Exploit discovered, please patch it now …village-idiot.org — wordpress 2.0.5 vulnerability http://www.village-idiot. [...]

  5. Yuliana Said:

    I used google translate to understand, because my English so bad. I think this great article. Thank for sharing.

  6. Perícia Digital » Blog Archive » Direito Digital: O lado bom e mau dos Plugins do Wordpress! Said:

    [...] [1] http://blog.mypapit.net/2007/01/a-wordpress-html-exploit-discovered-please-patch-it-now.html [...]

  7. Blogueiros correm riscos em provedores de conteúdo « Tatarana Said:

    [...] publicadas desde uma simples manutenção de html, que pode gerar o “defacing” do blog ou a delação de posts a falhas que permitem a exploração por “spam link injection” principalmente em códigos [...]

  8. Data Fanning Assessoria Empresarial - Blogueiros correm riscos em provedores de conteúdo Said:

    [...] publicadas desde uma simples manutenção de html, que pode gerar o “defacing” do blog ou a delação de posts a falhas que permitem a exploração por “spam link injection” principalmente em códigos [...]

  9. Blogueiros correm riscos em provedores de conteúdo « STANDEUTER Said:

    [...] publicadas desde uma simples manutenção de html, que pode gerar o “defacing” do blog ou a delação de postsa falhas que permitem a exploração por “spam link injection” principalmente em códigos [...]

Leave a Comment

Subscribe by email

Enter your Email