Welcome Guest ( Log In | Register)



 
Reply to this topicStart new topic
> Wordpress 2.1.1 Found To Be Dangerous
rvalkass
post Mar 3 2007, 10:43 AM
Post #1


apt-get moo
Group Icon

Group: [MODERATOR]
Posts: 2,055
Joined: 28-May 05
From: Hertfordshire, England
Member No.: 7,593
Spam Patrol



The 2.1.1 release of Wordpress (the latest release until 12 hours ago) has been found to contain an exploit that allows people to execute any code they want. According to Wordpress it only affects downloads in the last 3 or 4 days, but just to be sure, everyone is recommended to upgrade to 2.1.2 immediately. Wordpress have made an announcement explaining exactly what happened.

Personally I think it is worrying that something like this could happen. I just hope that Wordpress are dramatically improving the security of their servers to guarantee that this will never happen again. Then again it is reassuring to see it was picked up and fixed relatively quickly and the information has been distributed.
Go to the top of the page
 
+Quote Post
shigajet
post Mar 3 2007, 01:59 PM
Post #2


"Betsuni"
***********

Group: Members
Posts: 1,023
Joined: 9-April 05
From: Japan
Member No.: 5,445



I just installed WordPress 2.1 last night, and was just going to upgrade to 2.1.1 when I had some time over the weekend. Good thing I didn't. Thanks for the heads up, rvalkass.
Go to the top of the page
 
+Quote Post
darran
post Mar 3 2007, 02:39 PM
Post #3


Privileged Member
*********

Group: Members
Posts: 660
Joined: 31-August 06
From: Singapore
Member No.: 29,189



This is freaky, when I logged into my admin panel and saw this news in the announcement, I immediately downloaded 2.1.2 and uploaded it into my site. I am thankful WordPress has shown to be diligent and tip top in terms of service. Imagine if those crackers actually executed remote procedures, what would have been the consequences? I have already made a post on my site regarding this as well smile.gif

http://darran.trap17.com/2007/03/03/wp-211-is-dangerous/
Go to the top of the page
 
+Quote Post
master_bacarra
post Mar 4 2007, 05:37 PM
Post #4


I'm back... well, sort of.
*********

Group: [HOSTED]
Posts: 697
Joined: 26-December 05
From: somewhere in the middle of nowhere
Member No.: 16,226
Spam Patrol



i've read about this on my professor's blog, although i don't remember which version is installed in my blog. eh??? i rarely have time to update my blog, what more to upgrade it. it's kind of a hassle, especially since there are almost always updates to their program. i mean in just a span of a day they could probably jump from 2.1.1 to 2.1.2. my point is not everyone has the luxury of time to update their files, and if problems like these arise, it's very alarming.

oh well.
Go to the top of the page
 
+Quote Post
delivi
post Mar 4 2007, 06:33 PM
Post #5


Trap Grand Marshal Member
***********

Group: [HOSTED]
Posts: 1,300
Joined: 11-January 06
From: Chennai, India
Member No.: 16,932



Thanx for sharing the info and alerting us. I was planning to upgrade all my WP 2.1 blogs to WP 2.1.1, but thank god I didn't do it. I've to upgrade them to WP 2.1.2 or wait till the cPanel guys update it in fantastico.
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Are Mobile Phones Dangerous?(110)
  2. I Found A Site That Sends Money To Your Paypal(10)
  3. The Sims 2 Nightlife Expansion(10)
  4. Operating System Not Found(13)
  5. Thc Found To Kill Leukemia Cells(12)
  6. New, Earth-like Planet Found(25)
  7. Watermark Your Image With Simple Php Script(34)
  8. A Natural Treatment That Works?, Neem Trees(6)
  9. Sherwood A New Mmorpg I Found(20)
  10. Great Website I Found(12)
  11. How I Got Here.(6)
  12. Found Free Mobile Games Wallpapers And Themes(2)
  13. Blogger Vs. Wordpress(4)
  14. Everything Is Dangerous!(10)
  15. I Am Using A Free Antivirus That I Found On The Web(5)
  1. Wordpress 2.5 Released(3)
  2. Wordpress Backup For A Server Move(2)
  3. Review My Wordpress Theme(7)
  4. A:/ Drive Not Found(4)
  5. Sites Down After The Upgrade(8)
  6. Too Many Supplements Can Be Dangerous!(1)
  7. I Found Out What Lorem Ipsum Was Yesterday.(6)
  8. Found A New Site(3)
  9. Jack Thompson Found Guilty On 27 Of 31 Misconduct Charges(0)
  10. My Minimalist Wordpress Theme(3)
  11. Wordpress Upgrade Notification(3)
  12. Amazing Software(0)
  13. Wordpress Categories Disappear(4)


 



- Lo-Fi Version Time is now: 26th July 2008 - 09:19 AM