[wp-trac] [WordPress Trac] #21420: Login without salted MD5 Password

WordPress Trac wp-trac at lists.automattic.com
Mon Jul 30 14:29:31 UTC 2012


#21420: Login without salted MD5 Password
--------------------------+-----------------------
 Reporter:  shubhamoy     |       Owner:
     Type:  defect (bug)  |      Status:  reopened
 Priority:  normal        |   Milestone:
Component:  General       |     Version:  3.4.1
 Severity:  normal        |  Resolution:
 Keywords:  close         |
--------------------------+-----------------------

Comment (by ocean90):

 > An attacker places a SymLink Attack on the server and reads the wp-
 config.php of a wordpress powered site. After that accesses the database

 Nothing about a !WordPress related issue yet, so there is already
 something wrong before somebody changes the table.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/21420#comment:6>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list