WordPress Vulnerability in Older Versions < 2.8.4

This is a discussion on WordPress Vulnerability in Older Versions < 2.8.4 within the Web Design & Development forums, part of the Design & Development category; There is currently a "new" vulnerability in older versions of Wordpress WordPress › Support » Question About Possible Hack of ...

Web Design & Development Discuss php, mysql, html or css related issues

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 12-09-2009, 09:11 AM
ikonic's Avatar
Moderator
 
Join Date: Sep 2008
Role in AM: Other
Posts: 378
Thanks: 1
Thanked 41 Times in 38 Posts
Default WordPress Vulnerability in Older Versions < 2.8.4

There is currently a "new" vulnerability in older versions of Wordpress

WordPress › Support » Question About Possible Hack of Site
Old WordPress Versions Under Attack « Lorelle on WordPress

If you use WordPress and haven't updated it yet then you probably should ASAP

For the techies - essentially non administrators can modify the permalink structure via a post request to the following which causes the php engine to eval or execute the data/arguments passed in by the http referrer.

/%&({${eval(base64_decode($_SERVER[HTTP_REFERER]))}}|.+)&%/
__________________
If the text above is green then this post is being made as a forum moderator - Forum Guidelines.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following User Says Thank You to ikonic For This Useful Post:


  #2  
Old 25-09-2009, 01:52 AM
AF Chatterbox
 
Join Date: Jun 2009
Role in AM: Affiliate
Posts: 107
Thanks: 8
Thanked 7 Times in 7 Posts
Default

I've spent the last two days upgrading all my blogs from an old wp version to the latest version, am i correct in saying that there is now an auto update function in wp? As I really don't want to update 50 sites manually again!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3  
Old 25-09-2009, 07:44 AM
ikonic's Avatar
Moderator
 
Join Date: Sep 2008
Role in AM: Other
Posts: 378
Thanks: 1
Thanked 41 Times in 38 Posts
Default

When you login there should be a link on the main admin screen to check for updates/download and install updates.
__________________
If the text above is green then this post is being made as a forum moderator - Forum Guidelines.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4  
Old 25-09-2009, 08:22 AM
HarveyJ's Avatar
AF Chatterbox
 
Join Date: Feb 2008
Role in AM: Merchant
Posts: 461
Thanks: 2
Thanked 20 Times in 18 Posts
Default

Hasn't WP had an auto-update feature since 2.8.1?
Although it doesn't work if the permissions aren't set correctly...
I know there used to be an auto-update plugin that was amazingly handy.
__________________
Affiliation Cash: It makes me money. It can make you money.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5  
Old 25-09-2009, 02:14 PM
AF Chatterbox
 
Join Date: Jun 2009
Role in AM: Affiliate
Posts: 107
Thanks: 8
Thanked 7 Times in 7 Posts
Default

Your both right, Im the idiot who didnt look before he started manually updating everything.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6  
Old 26-09-2009, 06:16 PM
spacey's Avatar
Member
 
Join Date: Sep 2008
Role in AM: None
Posts: 77
Thanks: 2
Thanked 0 Times in 0 Posts
Default

i updated but dont know much about back up files , very pleased to see latest version has theme change options that offers many choices ! ..... goof stuff
__________________
| 3dtvs | vegetarian | insured ? | car videos | Worldne.ws | Sports Talk |
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Bookmarks

Tags
&lt, <, older, versions, vulnerability, wordpress

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Tables in Wordpress Robyn Web Design & Development 6 25-05-2010 11:42 AM
Import DataFeeds into WordPress tection99 Web Design & Development 1 13-02-2009 01:09 PM
Looking for Ready-Made WordPress themes! neithel Web Design & Development 3 11-05-2008 09:45 AM

Powered by vBadvanced CMPS v3.2.0

All times are GMT +8. The time now is 01:45 AM.