[wp-trac] [WordPress Trac] #11104: 2.8.5 Injection Exploit

WordPress Trac wp-trac at lists.automattic.com
Wed Nov 11 15:10:12 UTC 2009


#11104: 2.8.5 Injection Exploit
--------------------------+-------------------------------------------------
 Reporter:  bradyk        |       Owner:  ryan                                                            
     Type:  defect (bug)  |      Status:  new                                                             
 Priority:  high          |   Milestone:  Unassigned                                                      
Component:  Security      |     Version:  2.8.5                                                           
 Severity:  blocker       |    Keywords:  dev-feedback 2nd-opinion exploit, injection, hack, malware, porn
--------------------------+-------------------------------------------------
Changes (by g30rg3x):

  * keywords:  exploit, injection, hack, malware, porn => dev-feedback 2nd-
               opinion exploit, injection, hack, malware,
               porn


Comment:

 Ok...[[BR]]
 But also, there is [http://expressionengine.com/forums/viewthread/134818/
 another] MediaTemple customer, who recently suffer the same kinda of
 injection but using ExpressionEngine.[[BR]]
 Unless is a shared bug across wordpress, drupal and expressionengine... it
 is starting to really look as MediaTemple security pitfall.[[BR]]
 [[BR]]
 I have seen in the kyle blog that he states that...[[BR]]
 "Wordpress, and MediaTemple, seem to agree with me that this is a
 Wordpress issue"[[BR]]
 Can this be confirmed with a dev?[[BR]]
 ryan is it really a wordpress issue?[[BR]]

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/11104#comment:3>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list