Full Disclosure mailing list archives

Dumbest bug of this month - Wordpress 2.8


From: omglol () hushmail me
Date: Sat, 01 Aug 2009 22:16:27 +0200

1. Visit <rantingwhitehatblog>.com and register as a subscriber
2. Visit wp-admin//options-writing.php and post gay p0rn using the 
noted e-mail address. / Search for interesting unprotected Plugin 
pages to gain shell

greetings to ZFO
and have fun at defcon

(bug was leaked to wp-security team so .. be quick :D )

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: