Archiv

Artikel Tagged ‘luecke’

Wolfgang Schäuble’s Homepage gehackt

11. Februar 2009

Auuuu … da hat es jemand mit der Sicherheit und der aktuellen Typo3 Sicherheitslücke wohl nicht allzu genau genommen was? Big Grin

brainhackde00662brainhackde00663brainhackde00664

Das muss doch seeeeehr schmerzhaft sein – oder? Winking

[ via ]

227 Brainhits [?] Tags: , , , , , ,

Wordpress 2.6.3 Sicherheitslücke gepatched

24. Oktober 2008

Gaahh. Am frühen morgen lese ich sowas immer gerne … Cow

A vulnerability in the Snoopy library was announced today.  WordPress uses Snoopy to fetch the feeds shown in the Dashboard.   Although this seems to be a low risk vulnerability for WordPress users, we wanted to get an update out immediately.  2.6.3 is available for download right now.  If you don’t want to download the whole release to get the security fix, you can download the following two files and copy them over your 2.6.2 installation.

  1. wp-includes/class-snoopy.php
  2. wp-includes/version.php

Secunia selbst stuft die Sicherheitslücke als “critical” ein …

Secunia Advisory:
SA32361

Critical:

Highly critical

Description:
A vulnerability has been discovered in Snoopy, which can be exploited by malicious people to compromise a vulnerable system.
Input passed to the "_httpsrequest()" function isn’t properly sanitised before being used in an "exec()" call. This can be exploited to inject arbitrary shell commands via a script calling the "fetch()" or "submit()" function with an URL controlled by the attacker.

Naja – Update erledigt. Die zwei Files eben rüberschieben war ja auch kein Akt Yin Yang

33 Brainhits [?] Tags: , , , , ,