Google Pack Free AntiVirus!
 

WordPress Template.php HTML Injection Vulnerability

Filed in: Security, WordPress — January 3rd, 2007

A cross-site scripting (XSS) vulnerability has been found in wp-admin/templates.php in WordPress. WordPress 2.0.5 and previous versions are affected. The National Vulnerability Database has marked the severity as 7.0 (High).

WordPress has fixed this for v2.0.6 and a patch has been released for v2.0.5.

The possible damage

Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible. — SecurityFocus.com

Read also:

[Thanks, JohnTP]

Read also:

6 Responses to “WordPress Template.php HTML Injection Vulnerability”

Comments Feed | TrackBack URL
  1. #1
    Latest Exploit In Wordpress | Wordpress Tutorials And Blogging Tips Says:

    [...] According to LiewCF, The National Vulnerability Database has reported this as severity 7.0 (high). [...]

  2. #2
    :: מיומניו של לקוח :: » ארכיון » בעיית אבטחה בוורדפרס (כל הגרסאות, כולל 2.0.5) Says:

    [...] אתמול אלעד הפנה אותי לפוסט בנדון. [...]

  3. #3
    malique Says:

    liew, how do i install this security patch?

    thanks in advanced. :)

  4. #4
    LcF Says:

    @malique: you can download the patched file at http://trac.wordpress.org/changeset/4665 and replace your existing file on the server. Please make sure you have a backup first.

  5. #5
    Azmeen Says:

    WordPress 2.0.6 has been released which includes this fix.

  6. #6
    El blog de Vitrubio » Actualización a la versión 2.0.6 de Wordpress Says:

    [...] corrección de un importante fallo de seguridad (descrito en el el blog LiewCF*), y descubierto por David Kierznowski*, que hace más que aconsejable la actualización. [...]

Leave a Reply

Subscribe without commenting