Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93098 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

WordPress update available


  • Please log in to reply
114 replies to this topic

#1 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 02 November 2006 - 06:30 AM

FYI...

- http://secunia.com/advisories/22683/
Release Date: 2006-11-02
Critical: Moderately critical
Impact: Unknown
Where: From remote
Solution Status: Vendor Patch
Software: WordPress 2.x ...
...The vulnerabilities have been reported in versions prior to 2.0.5.
Solution: Update to version 2.0.5.
Provided and/or discovered by: Reported by the vendor.
Original Advisory: http://wordpress.org...6/10/205-ronan/ ..."

:ph34r:

Edited by AplusWebMaster, 18 June 2010 - 05:33 AM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.

    Advertisements

Register to Remove


#2 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 02 January 2007 - 01:46 PM

FYI...

WordPress 2.0.5 vuln - fix available
- http://nvd.nist.gov/...e=CVE-2006-6808
Last revised: 1/2/2007
"...Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter.
Impact: CVSS Severity: 7.0 (High)
Range: Remotely exploitable ..."

> http://wordpress.org...ort/topic/99128
Posted: 2007-01-02
... http://trac.wordpres.../changeset/4665

:ph34r:

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#3 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 05 January 2007 - 11:24 AM

FYI...

- http://secunia.com/advisories/23595/
Release Date: 2007-01-05
Critical: Highly critical
Impact: Unknown
Where: From remote
Solution Status: Vendor Patch
Software: WordPress 2.x
...The vulnerability is reported in versions prior to 2.0.6.
Solution: Update to version 2.0.6.
Original Advisory: http://wordpress.org.../wordpress-206/
January 5, 2007

- http://wordpress.org/download/
"The latest stable release of WordPress (Version 2.0.6)..."

- http://www.securityf...rchive/1/456048

- http://www.securityf...rchive/1/456049

Edited by AplusWebMaster, 05 January 2007 - 01:27 PM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#4 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 29 January 2007 - 11:33 AM

FYI...

Wordpress vuln - update available
- http://secunia.com/advisories/23912/
Release Date: 2007-01-29
Critical: Less critical
Impact: Exposure of system information, Exposure of sensitive information
Where: From remote
Solution Status: Vendor Patch
...The vulnerability is reported in versions prior to 2.1.
Solution: Update to version 2.1*

WordPress (Version 2.1)
* http://wordpress.org/download/

- http://wordpress.org/development/
January 22, 2007
"...2.1 also includes over 550 bug fixes..."

.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#5 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 26 February 2007 - 06:30 AM

FYI...

- http://secunia.com/advisories/24306/
Release Date: 2007-02-26
Critical: Less critical
Impact: Cross Site Scripting
Where: From remote
Solution Status: Vendor Patch
Software: WordPress 2.x
...The vulnerability is confirmed in version 2.1. Prior versions may also be affected.
Solution: Update to version 2.1.1..."

Download: http://wordpress.org/download/

:ph34r:

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#6 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 04 March 2007 - 02:57 PM

FYI...

Wordpress 2.1.1 source backdoored!
- http://isc.sans.org/...ml?storyid=2349
Last Updated: 2007-03-04 15:37:15 UTC ~ "The Wordpress development team has a notification up on their blog that version 2.1.1 of Wordpress has been compromised, and code was added which allows remote code execution. This happened during a user-level compromise of one of their servers. While not all 2.1.1 downloads have been affected, they advise that everyone running this version should upgrade to version 2.1.2 immediately. This version is fully verified and is not backdoored..."

- http://wordpress.org...e-212/#more-199
"...It was determined that a cracker had gained user-level access to one of the servers that powers wordpress.org, and had used that access to modify the download file. We have locked down that server for further forensics, but at this time it appears that the 2.1.1 download was the only thing touched by the attack. They modified two files in WP to include code that would allow for remote PHP execution. This is the kind of thing you pray never happens, but it did and now we’re dealing with it as best we can. Although not all downloads of 2.1.1 were affected, we’re declaring the entire version dangerous and have released a new version 2.1.2* that includes minor updates and entirely verified files... We reset passwords for a number of users with SVN and other access, so you may need to reset your password** on the forums before you can login again."

* http://wordpress.org/download/
"...latest stable release of WordPress (Version 2.1.2)..."

** http://wordpress.org/support/

:ph34r:

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#7 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 09 April 2007 - 07:57 PM

FYI...

> http://wordpress.org/download/
"The latest stable release of WordPress (Version 2.1.3) is available..."

- http://wordpress.org/development/
April 3, 2007 ~ "...This update is highly recommend for all users... These releases include fixes for several publicly known minor XSS issues, one major XML-RPC issue, and a proactive full sweep of the WordPress codebase to protect against future problems..."

> http://nvd.nist.gov/...e=CVE-2007-1893

.

Edited by AplusWebMaster, 10 April 2007 - 03:43 AM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#8 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 21 May 2007 - 10:28 AM

FYI...

- http://secunia.com/advisories/25345/
Release Date: 2007-05-21
Critical: Moderately critical
Impact: Manipulation of data, Exposure of sensitive information
Where: From remote
Solution Status: Vendor Patch
Software: WordPress 2.x
...The vulnerability is confirmed in version 2.1.3. Prior versions may also be affected.
Solution: Update to version 2.2 ..."

> http://wordpress.org/download/
"The latest stable release of WordPress (Version 2.2) is available..."

.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#9 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 26 June 2007 - 08:27 PM

FYI...

WordPress vuln - update available
- http://secunia.com/advisories/25794/
Release Date: 2007-06-26
Critical: Moderately critical
Impact: Security Bypass, System access
Where: From remote
Solution Status: Vendor Patch
Software: WordPress 2.x, WordPress MU 1.x ...
The vulnerability is confirmed in WordPress 2.2 and reported in WordPress MU 1.2.2. Prior versions may also be affected.
Solution: Update to WordPress 2.2.1 or WordPress MU 1.2.3..."

- http://wordpress.org/download/
"The latest stable release of WordPress (Version 2.2.1)..."

- http://mu.wordpress.org/download/

:ph34r:

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#10 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 07 August 2007 - 05:16 AM

FYI...

Wordpress 2.2.2 and 2.0.11
- http://wordpress.org...s-222-and-2011/
August 5, 2007
"...two security-related releases available for both users of our main 2.2 branch and the legacy 2.0 branch. As these releases include only security and minor bugfixes they should not cause any plugin or theme compatibility issues.."

Download:
- http://wordpress.org/download/


.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.

    Advertisements

Register to Remove


#11 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 12 September 2007 - 06:13 AM

FYI...

- http://secunia.com/advisories/26771/
Release Date: 2007-09-12
Critical: Moderately critical
Impact: Cross Site Scripting, Manipulation of data
Where: From remote
Solution Status: Vendor Patch
Software: WordPress 2.x, WordPress MU 1.x
...The vulnerabilities are reported in Wordpress prior to 2.2.3 and Wordpress MU prior to 1.2.5a.
Solution:
Update to Wordpress version 2.2.3 or Wordpress MU version 1.2.5a...

> http://wordpress.org/download/
"...latest stable release of WordPress (Version 2.2.3)..."

.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#12 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 12 October 2007 - 07:42 PM

FYI...

WordPress (Version 2.3)
- http://wordpress.org/download/

Release notes:
- http://wordpress.org/development/
September 25, 2007 - "...This release includes native tagging support, plugin update notification, URL handling improvements, and much more..."

.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#13 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 29 October 2007 - 05:50 AM

FYI...

WordPress Version 2.3.1
- http://wordpress.org.../wordpress-231/
October 26, 2007 - "WordPress 2.3.1 is now available. 2.3.1 is a bug-fix and security release for the 2.3 series. 2.3.1 fixes over twenty bugs... Unfortunately, some security issues were found in 2.3..."

- http://wordpress.org/download/

.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#14 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 24 January 2008 - 08:13 AM

FYI...

- http://wordpress.org.../wordpress-232/
December 29, 2007 - "WordPress 2.3.2 is an urgent security release..."

WordPress Version 2.3.2 was comprised of security and bug fixes.
- http://codex.wordpre...Changelog/2.3.2

- http://wordpress.org/download/
"The latest stable release of WordPress (Version 2.3.2)..."

> http://secunia.com/advisories/28130/

. :oops:

Edited by AplusWebMaster, 24 January 2008 - 08:26 AM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.


#15 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 05 February 2008 - 08:39 PM

FYI...

WordPress 2.3.3 released
- http://wordpress.org/development/2008/
February 5, 2008 - "WordPress 2.3.3 is an urgent security release..."

WordPress Version 2.3.3 was comprised of security and bug fixes.
- http://codex.wordpre...Changelog/2.3.3

- http://wordpress.org/download/
"The latest stable release of WordPress (Version 2.3.3)..."

> http://secunia.com/advisories/28823/
Release Date: 2008-02-07

> http://nvd.nist.gov/...e=CVE-2008-0664
Last revised: 2/8/2008
----------------

WordPress MU vuln - update available
- http://secunia.com/advisories/28789/
Release Date: 2008-02-06
Critical: Moderately critical
Impact: Security Bypass, System access
Where: From remote
Solution Status: Vendor Patch
Software: WordPress MU 1.x
Solution: Update to version 1.3.2 or later...
> http://mu.wordpress.org/download/
The 1.3.3 version of WordPress MU is now available...

Edited by AplusWebMaster, 11 February 2008 - 04:35 PM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.

Related Topics



2 user(s) are reading this topic

0 members, 2 guests, 0 anonymous users