View Single Post
Old 08-11-2009, 08:48 AM  
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,212
Ok Crybabies: 2.8.3 wordpress remote admin password exploit

Before you make posts saying shit please understand this exploit before you go all bananas.

You can reset the admin password without confirmation, but you dont know the password, and unless you have access to the admin email account it does nothing.

http://www.milw0rm.com/exploits/9410

Proof of concept

Already a fix out, so dont cry about having to upgrade all the time, if you dont like the product, dont use it, simple.

fix, edit 1 line of the code

http://core.trac.wordpress.org/changeset/11798

__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote