|
|
|
Vulnerability Note VU#641456WordPress fails to properly sanitize input passed to the iz parameter in wp-includes/theme.phpOverviewWordPress fails to properly sanitize input to the iz parameter in wp-includes/theme.php, which could allow a remote, unauthenticated attacker to execute arbitrary commands.I. DescriptionWordPress is a blogging application that is written in PHP. WordPress 2.1.1 fails to properly sanitize input to the iz parameter in wp-includes/theme.php, Commands that are passed to the iz parameter are executed by the WordPress server.II. ImpactA remote, unauthenticated attacker may be able to execute arbitrary commands on a vulnerable WordPress system.III. SolutionApply an updateThis issue is addressed in WordPress 2.1.2.
References
This vulnerability was reported by Ivan Fratric. This document was written by Will Dormann.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||