[wp-trac] Re: [WordPress Trac] #4627: Link manager exploit?

WordPress Trac wp-trac at lists.automattic.com
Tue Oct 16 08:19:39 GMT 2007


#4627: Link manager exploit?
----------------------+-----------------------------------------------------
 Reporter:  cbdilger  |        Owner:  pishmishy
     Type:  defect    |       Status:  reopened 
 Priority:  normal    |    Milestone:  2.3.1    
Component:  Security  |      Version:  2.2      
 Severity:  normal    |   Resolution:           
 Keywords:            |  
----------------------+-----------------------------------------------------
Comment (by DD32):

 > Perhaps put one current_user_can() check at the top and die early?

 Allright, I'll do that.

 While i'm looking at it, the move case does nothing, Doesnt look to have
 been touched since the start of 2006.. I cant see anything in WP-admin
 refering to either move or deletebookmarks.

-- 
Ticket URL: <http://trac.wordpress.org/ticket/4627#comment:12>
WordPress Trac <http://trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list