Dale's Weblog

looking back it was easy.
Saturday 13 March

XSS Security Holes in WordPress

Posted by dale on Sat, 02 Oct 2004 21:46:16 EST

Security vulnerabilities have been found in WordPress that allows users to enter code into the site through certain urls (whose content is not checked).

Examples:
http://[victim]/wp-login.php?redirect_to=[code]
http://[victim]/wp-login.php?mode=bookmarklet&text=[code]
http://[victim]/wp-login.php?mode=bookmarklet&popupurl=[code]
http://[victim]/wp-login.php?mode=bookmarklet&popuptitle=[code]
http://[victim]/admin-header.php?redirect=1&redirect_url=%22;[code]//
http://[victim]/bookmarklet.php?popuptitle=[code]
http://[victim]/bookmarklet.php?popupurl=[code]]
http://[victim]/bookmarklet.php?content=[code]
http://[victim]/bookmarklet.php?post_title=[code]
http://[victim]/categories.php?action=edit&cat_ID=[code]
http://[victim]/edit.php?s=[code]
http://[victim]/edit-comments.php?s=[code]
http://[victim]/edit-comments.php?mode=[code]

XSS (cross-site scripting) holes are common in many php scripts and Wordpress isn’t the only effected blogging tool. LiveJournal and Blogger are also vulnerable.

Athlough this is a somewhat large security issue wordpress users shouldn’t be too worried, all scripts have bugs.

The Wordpress team are working on a 1.2.1 release to fix these issues. So look out for it.

Related links:
http://wordpress.org/support/4/13818
http://wordpress.org/support/7/13856
http://news.netcraft.com/archives/2004/09/30/security_holes_in_wordpress_blogging_tool.html
http://secunia.com/advisories/12683/

Below are the comments for this news item

Wieeerd. That's just absolutely scary. Still, it's not going to stop me from using WP but it does pose a bit of a security threat. *sigh*

1: Comment by Stuart - Sat, 02 Oct 2004 23:20:42 EST


Oh I wouldn't stop using Wordpress over it. There are always going to be issues like that. phpBB has had them, although they were fixed before they were known to the general geek population. I'd say in the next week or so you should see a patch. And then Wordpress 1.3 should come out sometime after. I'm looking forward to that.

2: Comment by dale - Sun, 03 Oct 2004 08:26:30 EST


BBCode:

urls become clickable

[b]place text in bold[/b]

[i]place text in italics[/i]

[quote]place text in a quote[/quote]

Comments? Please note that all HTML tags are removed from your post.

The URI to TrackBack this entry is: http://www.dalegroup.net//early05/archive/blog/newsid/trackback/149

Comments

Message:

Name (optional):

Email (not shown):

WWW (optional):






Copyright © Michael Dale 2004. Page generated in 0.0050 seconds FreeBSD Powered
Background on style 5 is used from squidfingers How are we going? 3 queries