bugtraq
[Top] [All Lists]

Re: WordPress Search Function SQL-Injection

To: Justin Frydman - Thinkweb Media <justin@thinkwebmedia.com>
Subject: Re: WordPress Search Function SQL-Injection
From: ascii <ascii@katamail.com>
Date: Wed, 28 Feb 2007 01:26:13 +0100
Cc: SaMuschie <samuschie@yahoo.de>, bugtraq@securityfocus.com, full-disclosure@lists.grok.org.uk, vuln-dev@securityfocus.com, webappsec@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: bugtraq-list@securepoint.com
Delivered-to: mailing list bugtraq@securityfocus.com
Delivered-to: moderator for bugtraq@securityfocus.com
In-reply-to: <0d0b4a392110a4f6f1ab2919c673be7f@localhost>
List-help: <mailto:bugtraq-help@securityfocus.com>
List-id: <bugtraq.list-id.securityfocus.com>
List-post: <mailto:bugtraq@securityfocus.com>
List-subscribe: <mailto:bugtraq-subscribe@securityfocus.com>
List-unsubscribe: <mailto:bugtraq-unsubscribe@securityfocus.com>
Mailing-list: contact bugtraq-help@securityfocus.com; run by ezmlm
References: <20070227203955.65267.qmail@web27812.mail.ukl.yahoo.com> <0d0b4a392110a4f6f1ab2919c673be7f@localhost>
User-agent: Thunderbird 1.5.0.9 (X11/20061206)
Justin Frydman - Thinkweb Media wrote:
> Can't replicate this in 2.0.7. Is this only for the 2.1.x branch then?

i have the same feeling

tested on multiple wp instances and can't reproduce on >= 2.0.1 <= 2.0.7

regards, Francesco 'ascii' Ongaro
http://www.ush.it/

<Prev in Thread] Current Thread [Next in Thread>