Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

January 3rd, 2012, 13:14 GMT · By Eduard Kovacs

BLOG

Hackers Can Exploit WordPress 3.3 Sites by Posting Article Comments

SHARE:

Adjust text size:

WordPress sites may be vulnerable to XSS attacks Enlarge picture - WordPress sites may be vulnerable to XSS attacks
Indian security researchers Aditya Modha and Samir Shah found a zero-day cross-site scripting (XSS) vulnerability in the recently released WordPress 3.3.

Modha and Shah tested the proof of concept on an Apache server, proving that by simply posting a comment on a WordPress website, an attacker can execute arbitrary code.

The proof of concept works by posting a comment on the targeted site, replacing the author, email and comment tags with the exact values found in the previous comment using a simple script. The server’s response will generate a 500 internal server error because a duplicate comment will be detected.

The vulnerability seems to affect only Internet Explorer browsers, Firefox, Safari, Chrome and Opera not being susceptible to such an attack.

Webmasters could mitigate the problem by making sure the error page is padded with enough characters so that its size is greater than 512 bytes even after gzip compression.
FILED UNDER:
POC
XSS
WordPress

TELL US WHAT YOU THINK:

2,103 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Hashes Used by PHP, ASP.NET, Java, Python and Ruby Vulnerable to DoS Attacks

phpMyAdmin 3.4.9 Closes Two Cross-Site Scripting Vulnerabilities

XSS Vulnerabilities Fixed in Fork CMS 3.1.7

Comodo Certificate Authority Website Vulnerable to XSS Attacks

Avast and Norman Websites Found Vulnerable to XSS Attacks

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM