Command Execution Vulnerability in WordPress Affecting all Versions命令执行漏洞,在WordPress影响所有版本
A command execution vulnerability has been found in WordPress’s handling of incoming cookie information which allows remote attackers to cause the program to execute arbitrary code if the PHP settings of register_globals has been set to On.命令执行漏洞已被发现在WordPress的处理传入的cookie信息,使远程攻击导致该程序执行任意代码,如果PHP的设置了register_globals已设置为上。
Already a perl and php exploit is available.已经是一个Perl和PHP的利用可用。 It affects WordPress version 1.5.1.3 and before when register_globals is set to On.它影响的WordPress版本1.5.1.3之前,当register_globals设置为上。 The information has been provided by Kartoffelguru.资料已经提供了kartoffelguru 。
WordPress developers are working on a fix.在WordPress的开发人员正努力在一个修补程序。
Update: Add the line to your php.ini file (in WordPress root) for a fix:更新:行添加到您的php.ini文件(在WordPress根)为修复:
php_flag register_globals off php_flag register_globals的小康
Do it now.现在就这样做。
Note: This may affect functioning of some plugins which rely on php global variables being available.注:这可能会影响运作的一些插件,这依赖于PHP的全局变量被可用。
Filed under提起下 CMS Software CMS软件 , , Headline News头条新闻 , , Pro Blogging赞成Blogging , , Web网页 , , WordPress在WordPress | |
| |
RSS 2.0 2.0 | |
Trackback Trackback跟踪 this Article |此文章|
Email this Article电子邮件此文章
You may also like to read您也可以想读 |




August 13th, 2005 at 12:31 pm 2005年8月13日在下午12时31分
[...] [Source: Simple Thoughts] [...] [ … …来源:简单的思考] [ … … ]
August 13th, 2005 at 3:03 pm 2005年8月13日在下午3时03分
Podz has posted a fix here podz发布了一个修补程序在这里
August 13th, 2005 at 3:05 pm 2005年8月13日在下午3时05分
I’ll try again (!) - Podz has posted a fix here:我会再试一次( ! ) -p odz发布了一个修补程序在这里: http://www.tamba2.org.uk/T2/archives/2005/08/13/stop-your-blog-being-hacked/ http://www.tamba2.org.uk/t2/archives/2005/08/13/stop-your-blog-being-hacked/
August 13th, 2005 at 4:20 pm 2005年8月13日在下午4时20分
[...] Foi anunciada, pelo site SecuriTeam, especializado em segurança de sistemas e aplicativos de computadores, uma vulnerabilidade presente na versão 1.5.3 que afeta todas as versões do WordPress, inclusive a mais recente, 1.5.3, e que deve ser corrigida imediatamente. [ … … ]已公布阿农西亚达,之网站securiteam , especializado在德安全产品系统e应用程序电脑,一vulnerabilidade presente娜版本1.5.3阙afeta托达作为versões做的WordPress ,其中包括一看recente , 1.5.3 ,电子商务阙的发展情况丝氨酸corrigida imediatamente 。 [...] [ … … ]
August 13th, 2005 at 7:55 pm 2005年8月13日在下午7点55分
Thanks Tom for the update.感谢汤姆为更新。