[wp-trac] Re: [WordPress Trac] #4690: Wordpress options.php SQL Injection Vulnerability

WordPress Trac wp-trac at lists.automattic.com
Wed Aug 1 17:25:05 GMT 2007


#4690: Wordpress options.php SQL Injection Vulnerability
-------------------------------------+--------------------------------------
 Reporter:  BenjaminFlesch           |        Owner:  Nazgul     
     Type:  defect                   |       Status:  assigned   
 Priority:  high                     |    Milestone:  2.3 (trunk)
Component:  Security                 |      Version:  2.2.1      
 Severity:  major                    |   Resolution:             
 Keywords:  has-patch needs-testing  |  
-------------------------------------+--------------------------------------
Comment (by markjaquith):

 Nazgul, we can't use that fix now (although it is planned for 2.4) because
 it will break a lot of things.  For now, we have to do our escaping
 outside of those functions.

-- 
Ticket URL: <http://trac.wordpress.org/ticket/4690#comment:4>
WordPress Trac <http://trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list