<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.7" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Wordpress Vulnerability, CSRF/XSS Details</title>
	<link>http://www.justinshattuck.com/2007/03/02/wordpress-vulnerability-csrfxss-details/</link>
	<description>mental diuretic</description>
	<pubDate>Wed, 20 Aug 2008 18:31:22 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.7</generator>

	<item>
		<title>by: Stefan Friedli</title>
		<link>http://www.justinshattuck.com/2007/03/02/wordpress-vulnerability-csrfxss-details/#comment-5494</link>
		<pubDate>Mon, 05 Mar 2007 09:03:16 +0000</pubDate>
		<guid>http://www.justinshattuck.com/2007/03/02/wordpress-vulnerability-csrfxss-details/#comment-5494</guid>
					<description>Hi Justin

You're mixing up two things here: First issue is a lack of input validation for various parameters in the regular release of wordpress that I described in my advisory you linked in your article.

The second thing you're mentioning is the maliciously manipulated version of 2.1.1 that was available from Wordpress official download site for a while due to a badly secured server. Several files of this distribution were backdoored by the intruder, so mod_security won't most possibly save your a** there ;).

Cheers
Stefan</description>
		<content:encoded><![CDATA[<p>Hi Justin</p>
<p>You&#8217;re mixing up two things here: First issue is a lack of input validation for various parameters in the regular release of wordpress that I described in my advisory you linked in your article.</p>
<p>The second thing you&#8217;re mentioning is the maliciously manipulated version of 2.1.1 that was available from Wordpress official download site for a while due to a badly secured server. Several files of this distribution were backdoored by the intruder, so mod_security won&#8217;t most possibly save your a** there ;).</p>
<p>Cheers<br />
Stefan
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
