Wordpress is vulnerable to threats » Computer internet security  
Computer and internet security news
computer and networking security portal
 
|
|
|
News
|
Advertise
|
|
Products
|
Contact

Wordpress is vulnerable to threats



Wednesday, May 14, 2008, 11:10
This news item was posted in System Bugs category and has 0 Comments so far.

A major security vulnerability has been discovered in the popular WordPress blogging software. The vulnerability may allow an attacker to bypass security restrictions. Being able to bypass security restrictions would allow someone the ability to post malicious code that could attack visitors to that site. When the “backend” server application is vulnerable it makes everyone more vulnerable. WordPress is one of the most popular blogging applications on the Internet. Its rich features and vast number of available plugins allow it to be used as a poor-man’s Content Management System (CMS). WordPress is open source which allows anyone to modify the code or build plugins to meet their requirements. Being “Open Source” is usually a good thing. But when a security fix comes out for an Open Source server application it means the bad guy only has to compare the old code with the new code to figure out where the problem lies. From there it is usually not too hard to figure out how to exploit it. Now that WordPress has released their security fix anyone with a little PHP talent can figure out what was fixed and thus what was vulnerable. WordPress is used on hundreds of thousands of sites. Many popular sites use it, including some anti-hacker security sites (lucky for us we use something else). The vulnerability allows someone to bypass the security restrictions and thus presumably be able to elevate their rights to the equivalent of the site administrator. This would allow them to post their own code that could be used for such things as capturing visitors login passwords or posting malicious “drive-by” executables (would require taking advantage vulnerabilities on the visitors computer) that could install spyware or other malicious programs (the sky is the limit at that point).

Related posts:

  1. Matt Cutt gave new wordpress security tips
  2. Wordpress Security Update
  3. WordPress 2.1.3 Akismet Vulnerability
  4. WordPress 2.1.3 SQL Injection Vulnerability
  5. WordPress 2.1.1 Users at Risk
  6. wordpress plugin security issue

Related posts brought to you by Yet Another Related Posts Plugin.





Tagged with: , ,

You can leave a response, or trackback from your own site.

Leave a Reply





:::: Recent entries


 
Join My Community at MyBloglog!



My BlogCatalog BlogRank

Computers Blogs - Blog Top Sites