Browse by Tags

All Tags » Blogging (RSS)
I don't think I got a chance to thank everyone at MyITforum for awarding me the "Most Prolific Blogger Award", I really appreciate it!! From what Ron told me, this blog generated 1.2 million...
Posted by cmosby | with no comments
Once the vulnerability has been exploited, the script then creates the folder named 1 in the users wp-contents folder. This script then populates the created folder with a list of various spammy Web page...
The scandal that wasn't... Following on from yesterday's EEG Web site hack , a collection of recently registered sites, hosted on blogspot.com, claim to have obtained an explicit video featuring...
WordPress XML-RPC Post Edit Vulnerability Secunia Advisory: SA28823 Release Date: 2008-02-07 Critical: Less critical Impact: Security Bypass Manipulation of data Where: From remote Solution Status: Vendor...
WordPress MU File Upload and Security Bypass Secunia Advisory: SA28789 Release Date: 2008-02-06 Critical: Moderately critical Impact: Security Bypass System access Where: From remote Solution Status: Vendor...
WordPress WP-Footnotes Plugin "admin_panel.php" Cross-Site Scripting Secunia Advisory: SA28772 Release Date: 2008-02-04 Critical: Less critical Impact: Cross Site Scripting Where: From remote...
Posted by cmosby | with no comments
Wordspew Plugin for Wordpress "id" SQL Injection Vulnerability Secunia Advisory: SA28767 Release Date: 2008-02-04 Critical: Moderately critical Impact: Manipulation of data Where: From remote...
Posted by cmosby | with no comments
WordPress WassUp Plugin "to_date" SQL Injection Vulnerability Secunia Advisory: SA28702 Release Date: 2008-01-31 Critical: Moderately critical Impact: Manipulation of data Exposure of sensitive...
WordPress AdServe Plugin "id" SQL Injection Secunia Advisory: SA28708 Release Date: 2008-01-30 Critical: Moderately critical Impact: Manipulation of data Exposure of sensitive information Where...
WordPress WassUp Plugin 'spy.php' SQL Injection Vulnerability Bugtraq ID: 27525 Class: Input Validation Error CVE: Remote: Yes Local: No Published: Jan 30 2008 12:00AM Updated: Jan 31 2008 03:27AM...
WordPress WP-Cal Plugin "id" SQL Injection Secunia Advisory: SA28683 Release Date: 2008-01-29 Critical: Moderately critical Impact: Manipulation of data Exposure of sensitive information Where...
WordPress Draft Information Disclosure Secunia Advisory: SA28130 Release Date: 2007-12-19 Critical: Less critical Impact: Security Bypass Exposure of sensitive information Where: From remote Solution Status...
Rod sums thing up that happened recently so well, there is no need to rewrite it. ;-) Thanks Rod for the kind words! I am not sure how this interest from Symantec is going to play out but I do know from...
Posted by cmosby | with no comments
WordPress XSS Exploit Solves Problems… and Creates More! A proof-of-concept code exploiting newly discovered XSS vulnerabilities for the latest version of Wordpress (2.2.1) was posted today on a security...
March 2, 2007 WordPress 2.1.1 dangerous, Upgrade to 2.1.2 By Matt . Filed under Releases . Long story short: If you downloaded WordPress 2.1.1 within the past 3-4 days, your files may include a security...
MOPB Starts with 3 Bugs March 2nd, 2007 by Miray Lozada Following the footsteps of MOAB , MOKB , MOBB , the Hardened-PHP Project declares March as the Month of PHP Bugs and promptly publishes three PHP...
not bad for a blog with no content…