1/17/2006 ↓

WP-Stats Plugin Vulnerability

If you like this post, please subscribe to our RSS feed to read our new posts every day.

WP-Stats Plugin Vulnerability: An SQL injection vulnerability has been found in the plugin WP-Stats version 2.x where the author parameter is not sanitized before it is used. At the time of writing, I am not sure which WP-Stats Secunia is talking about. However, if you use version 2.x of this plugin, please disable it till a patch is developed.
[EDIT]: See here for the new version that fixes the vulnerability. Thanks Ronald.

1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...

Friends

Translate

Translate to German Translate to Spanish Translate to French Translate to Italian Translate to Portuguese Translate to Japanese Translate to Korean Translate to Russian Translate to Chinese

Latest Videos

2 Comments | Leave a comment | Comments RSS

  1. Sicherheitslcke in WP-Stats Plugin

    Gemss Secunia weist das Wordpress Plugin WP-Stats eine Sicherheitslcke auf, der es Angreifern erlaubt, SQL-Code auf dem Server auszufhren:
    Preddy has discovered a vulnerability in WP-Stats, which can be exploited by malicious people to conduct SQL…

    BloggingTom — 01/17/2006 @ 10:57 am
  2. It’s gamerz WP-Stats, and the problem is solved.

    [Reply]

    Ronald (1 comments.) — 01/17/2006 @ 1:21 pm

Leave a comment

Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required, will not be published)


S2