Bug#435848: Several vulnerabilities detected (XSS, SQL-injection)

2007-08-03 Thread Daniel Leidert
Kai Hendry wrote: > Thanks for the heads up Daniel. > > I don't think stable 2.0.x is vulnerable because there is no > wp-admin/upload.php in that branch. JFTR: Well, these are at least 8 vulnerabilities and only 2 seem to refer to upload.php. But I just stumbled over a related report today, so I

Bug#435848: Several vulnerabilities detected (XSS, SQL-injection)

2007-08-03 Thread Kai Hendry
Thanks for the heads up Daniel. I don't think stable 2.0.x is vulnerable because there is no wp-admin/upload.php in that branch. I think upstream are ready-ing 2.2.2. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#435848: Several vulnerabilities detected (XSS, SQL-injection)

2007-08-03 Thread Daniel Leidert
Package: wordpress Version: 2.2.1-1 Severity: important Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, Today I read about several newly discovered vulnerabilities in wordpress: http://mybeni.rootzilla.de/mybeNi/2007/wordpress_zeroday_vulnerability_roundhouse_kick_and_why_i_nea