{"id":229382,"date":"2005-07-04T23:22:10","date_gmt":"2005-07-04T23:22:10","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/php-blogging-apps-open-to-xml-rpc-exploits\/"},"modified":"2016-08-18T19:58:22","modified_gmt":"2016-08-18T19:58:22","slug":"php-blogging-apps-open-to-xml-rpc-exploits","status":"closed","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/php-blogging-apps-open-to-xml-rpc-exploits\/","title":{"rendered":"PHP Blogging Apps Open to XML-RPC Exploits"},"content":{"rendered":"<p>http:\/\/news.netcraft.com\/archives\/2005\/07\/04\/php_blogging_apps_vulnerable_to_xmlrpc_exploits.html<br \/>\n&#8220;Many popular PHP-based blogging, wiki and content management programs can be exploited through a security hole in the way PHP programs handle XML commands. The flaw allows an attacker to compromise a web server, and is found in programs including PostNuke, WordPress, Drupal, Serendipity, phpAdsNew, phpWiki and phpMyFAQ, among others.&#8221;<\/p>\n<p>What are WP users on shared servers supposed to do? &#8220;Disabling XML-RPC features is the recommended workaround&#8221; &#8211; How to do?<\/p>\n<p>If you control the server, try this:<br \/>\n<code><br \/>\npear clear-cache<br \/>\npear upgrade XML_RPC<\/code><\/p>\n","protected":false},"template":"","class_list":["post-229382","topic","type-topic","status-closed","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/229382","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/229382\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=229382"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}