[wp-hackers] WordPress <= 2.8.5 Unrestricted File Upload	Arbitrary PHP Code Execution
    Ken Newman 
    Ken at adcSTUDIO.com
       
    Wed Nov 11 20:16:47 UTC 2009
    
    
  
Couldn't you just block anything with *.php.* from being uploaded thru 
wordpress?
    
    
More information about the wp-hackers
mailing list