[wp-trac] Re: [WordPress Trac] #5367: Wordpress cookie authentication vulnerability

WordPress Trac wp-trac at lists.automattic.com
Tue Nov 20 01:07:39 GMT 2007


#5367: Wordpress cookie authentication vulnerability
-----------------------+----------------------------------------------------
 Reporter:  sjmurdoch  |        Owner:  anonymous
     Type:  defect     |       Status:  new      
 Priority:  normal     |    Milestone:  2.4      
Component:  Security   |      Version:  2.3.1    
 Severity:  normal     |   Resolution:           
 Keywords:             |  
-----------------------+----------------------------------------------------
Comment (by ryan):

 That scheme sounds good to me, but since we currently support PHP back to
 4.2 we have to be aware of portability problems.  I don't think we can
 count on sha1() or the hash module, for example.

-- 
Ticket URL: <http://trac.wordpress.org/ticket/5367#comment:4>
WordPress Trac <http://trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list