Forums

"Php is vulnerable" or "wordpress is vulnerable"? (8 posts)

  1. Kguy
    Member
    Posted 6 years ago #

    i have just read this news and i searched in this forums but couldnt find anything. i dont know i am in right place or not...

    http://news.netcraft.com/archives/2005/07/04/php_blogging_apps_vulnerable_to_xmlrpc_exploits.html

    but as i read and understand, we are all now vulnerable now.

  2. Mark (podz)
    Support Maven
    Posted 6 years ago #

    No we are not.

    http://wordpress.org/support/topic/38263

    You searched ?

  3. angsuman
    Member
    Posted 6 years ago #

    PHP as a language is not vulnerable. Lots of PHP based blogging and cms software installations are currently vulnerable because they use a widely used phpxmlrpc library which has a remote script execution vulnerability. WP 1.5.1.2 and earlier versions are vulnerable. Additionally WordPress 1.5.1.2 and earlier versions has several other vulnerabilities too like cross-site scripting, sql injection etc.

  4. skippy
    Member
    Posted 6 years ago #

    Note that WordPress does not use the PHPXMLRPC library.

    Ryan Boren:

    Not relevant to WP. We don't use the php libraries. Ours is a different but similar XMLRPC exploit. There was ours, the php one, and the PEAR one all at the same time. Ours was unique to us whereas the php and PEAR ones affected lots of projects.

  5. angsuman
    Member
    Posted 6 years ago #

    At the core the problem was the same - not sanitizing the query string parameteres (arguments to xmlrpc.php).

  6. Kguy
    Member
    Posted 6 years ago #

    Thank You so much! WordPress is one of the best web-based software and it should be always like this, should rock the web!

    regards ;)

  7. jonimueller
    Member
    Posted 6 years ago #

    And the above is why I'm scared to death to try to write anything in PHP. Because I don't have enough sense to close doors behind me, so to speak! The above is probably also a really good reason it's not much fun to be a web host right now!

  8. angsuman
    Member
    Posted 6 years ago #

    Look at secunia. There are now tons of critical security defects in wide ranging PHP products. makes you wonder isn't it?
    I said before php as a language is not vulnerable. But many of its libraries are. Simplicity comes at a price.

Topic Closed

This topic has been closed to new replies.

About this Topic

Tags

No tags yet.