Portal IT :: News, download, directory


Search: Sunday 27 May 2012











Add to Google Add to My Yahoo!


  Add to Favorites   Set Home Page





« may 2012
s m t w t f s
29 30 1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31 1 2
3 4 5 6 7 8 9







WordPress 2.6.5 Update Deals With XSS Vulnerability
Published on Security  |  November 28, 2008, 9:26

A fresh new WordPress update comes to knock out a cross-site scripting (XSS) flaw.

According to a WordPress announcement, the issue in question should not alarm WP blogers, unless several conditions are met:

“The security issue is an XSS exploit discovered by Jeremias Reith that fortunately only affects IP-based virtual servers running on Apache 2.x. If you are interested only in the security fix, copy wp-includes/feed.php and wp-includes/version.php from the 2.6.5 release package.”

In addition, WordPress 2.6.5 comes with 3 other fixes:
- prevents accidentally saving post meta information to a revision
- prevents XML-RPC from fetching incorrect post types.
- adds some user ID sanitization during bulk delete requests

WordPress released version 2.6.5 directly after 2.6.3. There never was nor will be an officiall WordPress 2.6.4. The only “version” bearing this name is a fake package released by some nice people, better-known as “hackers”. So just try to avoid such a version, were it to come your way.



Rate this       Low   High
Curent Rating: 3.1/5 by 12 users
 Print       Email      IM 




 
More Security News
 
Daily News Alert

 
Advertising
 
Top Rated Security News This Month