PDA

View Full Version : WordPress metaWeblog.editPost Post Arbitrary Modification (xmlrpc, Exploit, Patch)



newsbot
03-02-2008, 01:39 AM
WordPress (http://wordpress.org/) is "a state-of-the-art semantic personal publishing platform with a focus on aesthetics, web standards, and usability". A vulnerability in the way Wordpress handles the metaWeblog.editPost allows remote attackers that have just subscriber privileges to modify the posts of other users.

http://www.securiteam.com/unixfocus/5HP010KNFK.html