Latest Comments
"I would like to try the special 30 day offer"
by Julia Keene | Sep 9, 2008 1:02 AM
 
"hi.. i like google chrome. I need to know if in future, google is willing to upgrade google ..."
by george s | Sep 7, 2008 1:52 AM
 
"I urge every business person and IT person, management or staff, to get hold of a copy of "I.T. ..."
by John Franks | Sep 6, 2008 1:20 AM
 
""Google arrived on the browser scene with the launch of Chrome"... Seems a bit misplaced to ..."
by Jeme | Sep 5, 2008 12:33 AM
 
"Yes? And? So what? What were the recommendations of the report? What is the point of this ..."
by Tim | Sep 4, 2008 2:02 PM

WordPress releases update; unpatched vulnerability remains

  • Email a Friend
  • Print Page
Version 2.3.3 – released this week – repairs the flaw in XML-RPC, a remote procedure call protocol that can be exploited by sending specially crafted HTTP requests.

In lieu of updating, administrators can download the xmlrpc.php script from the WordPress site and replace the existing script.

Vulnerability tracking firm Secunia rated the flaw “less critical.”

“The [original] xmlrpc.php script does not properly restrict access to the edit functionality,” the Secunia advisory said, noting that exploitation requires valid credentials.

In addition, a SQL injection flaw has emerged in the WP-Forum plug-in, a software extension that can place forums on WordPress sites, according to WordPress.

The unpatched bug can steal usernames, password hashes and email addresses from users and administrators, according to Secunia, which ranked the flaw moderately critical.

WordPress developers suggest users disable the plug-in until an update can be pushed out.

Experts have said blogs present a ripe target for hackers because many businesses fail to keep the supporting software up-to-date. Duke University Law School's website recently suffered a major data breach that was made possible by a vulnerability in the site's third-party blogging software.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Patch Management Whitepapers