WordPress Fixed XSS Problem



Quick Search for

Find out more about

WordPress, as special blogging network fix XSS (cross-site scripting) in the WordPress blogging software. WordPress 2.6.5 also has three bugs that are associated with the performance and stability of the open-source package. Repairs to the weakness XSS limited to the specific setup including IP virtual servers running on Apache 2.x.

In the setup may be used by hackers to install the system with JavaScript evil code from the domain, under their control. WordPress has been jump from version 2.6.3 to 2.6.5 in order to prevent confusion with the version 2.6.4 that several months ago has been released, but have affected black hat via fake site. Sysadmin will directly download the code on the backdoor for hackers exploit weaknesses in the WordPress blogging package.

Exploitation cases of XSS a weakness in wordpress is found by Jeremias Reith which affected effect on the IP belong to the virtual server running on Apache 2.x. To repair XSS security weaknesses in the wordpress, it can copy “wp-includes/feed.php and wp-includes/version.php” from the package WordPress 2.6.5.


This entry was posted on Sunday, November 2nd, 2008 at 8:57 am and is filed under network & sites, software. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Reply