PHP XMLRPC Remote Code Execution Vulnerability affecting Popular Blogging and CMS Platforms like WordPress 1.5.1.2 (and lower), PostNuke, Drupal, b2evolution TikiWiki etc.July 5th, 2005 PHPXMLRPC aka XML-RPC For PHP is a PHP implementation of the XML-RPC, web RPC protocol, and was originally developed by Edd Dumbill of Useful Information Company. As of the 1.0 stable release, the project has been opened to wider involvement and moved to SourceForge.
Macromedia Flash Player 7 Remote Code Execution VulnerabilityNovember 14th, 2005 A vulnerability has been reported in Macromedia Flash Player 7, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to missing validation of the frame type identifier that is read from a SWF file.
Serious Security Vulnerabilities of WordPress 1.5.1.2 and belowJuly 5th, 2005 WordPress is a very popular personal publishing platform aka blogging platform (with a primitive CMS) in use all over the web. There are a number of serious security vulnerabilities in WordPress that may allow an attacker to ultimately run arbitrary code on the vulnerable system.
Microsoft PowerPoint Suffers From Memory Corruption Security VulnerabilityJuly 18th, 2006 Naveed has discovered a vulnerability in Microsoft PowerPoint, which potentially can be exploited to compromise any user's system. The vulnerability has been confirmed on Windows XP SP2 with a fully patched PowerPoint 2003.
How To Get Older Versions of WordPressJanuary 18th, 2007 WordPress is a popular blogging software which is used in this blog and lot of blogs on the internet. One of the frequently asked questions was how can we get older versions of WordPress.
Linux Worm Exploits PHP XMLRPC VulnerabilityNovember 9th, 2005 There are few reports of an attack by a new Linux worm called Lupper which exploits a well known PHP XMLRPC implementation vulnerability. PHP XMLRPC implementation is used in a large number of popular web applications such as PostNuke, Drupal, b2evolution, Xoops, PHPGroupWare, TikiWiki etc.
Serious Security Vulnerabilities in Outpost Firewall Pro & Lavasoft Personal FirewallJuly 18th, 2006 Bipin Gautam has reported a vulnerability in Outpost Firewall Pro, which can be exploited by local users to cause a DoS (Denial of Service). The vulnerability is caused due to an unspecified error in the Virtual Firewall driver (filtnt.sys) and can be exploited to crash the system by e.g.
Translator Plugin Pro Fully Supported On WordPress 2.x, 2.1.x, 2.2.x & 2.3.x (development)June 8th, 2007 Angsuman's Translator Plugin Pro is fully supported on all the latest versions of WordPress viz. WordPress 2.0.x, 2.1.x, 2.2.x Release versions as well as WordPress 2.3 development version.
Cross-Site Scripting Vulnerability in Apache mod_imap ModuleDecember 16th, 2005 A cross-site scripting (XSS) vulnerability has been discovered in the Apache httpd server's mod_imap module which allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps. Input passed to the image map "Referer" directive in "mod_imap" isn't properly sanitised before being returned to the user.
Is there a need to upgrade beyond WordPress 1.5.1.2 in near future?June 20th, 2005 I looked at the proposed feature set summary for WordPress 1.6. Mostly UI changes, few extra plugin hooks etc.
Xoops CMS SQL Injection Vulnerability ReportedJune 29th, 2006 KeyCoder has discovered a vulnerability in the MyAds module for Xoops, which can be exploited by malicious people to conduct SQL injection attacks. Input passed to the "lid" parameter in annonces-p-f.php isn't properly sanitised before being used in a SQL query.
Mambo / Joomla SQL Injection VulnerabilityJune 19th, 2006 rgod has discovered a vulnerability in Mambo & Joomla, which can be exploited to conduct SQL injection attacks. Input passed to the "Name" field when submitting a web link isn't properly sanitised before being used in a SQL query.
Free WordPress Plugin To Disable wlw_manifest & EditURI Link From WordPress Blog HeaderJune 29th, 2008 Newer versions of WordPress (2.3.1 and above) adds two extra lines to your blog header. They are:
You need them to use Windows Live Writer to write to your WordPress blog.
Critical Vulnerability in Apple's iTunes for WindowsDecember 18th, 2005 A critical vulnerability, found in some versions of Apple's popular iTunes software, could enable attackers to remotely take over a user's computer, according to a warning issued by eEye. This flaw existed on the earlier version of iTunes 6 for Windows and was not addressed by the latest security update.
Mambo CMS Suffers From File Inclusion VulnerabilityJune 29th, 2006 Kw3[R]Ln has discovered a vulnerability in the MOD_CBSMS module for Mambo, which can be exploited to compromise a machine serving Mambo CMS. Input passed to the "mosConfig_absolute_path" parameter in mod_cbsms_messages.php isn't properly verified, before it is used to include files.
August 13th, 2005 at 12:31 pm
[...] [Source: Simple Thoughts] [...]
August 13th, 2005 at 3:03 pm
Podz has posted a fix here
August 13th, 2005 at 3:05 pm
I’ll try again (!) - Podz has posted a fix here: http://www.tamba2.org.uk/T2/archives/2005/08/13/stop-your-blog-being-hacked/
August 13th, 2005 at 4:20 pm
[...] Foi anunciada, pelo site SecuriTeam, especializado em segurança de sistemas e aplicativos de computadores, uma vulnerabilidade presente na versão 1.5.3 que afeta todas as versões do WordPress, inclusive a mais recente, 1.5.3, e que deve ser corrigida imediatamente. [...]
August 13th, 2005 at 7:55 pm
Thanks Tom for the update.