Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

January 4th, 2012, 07:38 GMT · By Eduard Kovacs

BLOG

WordPress 3.3.1 Released to Fix XSS Vulnerability

SHARE:

Adjust text size:

WordPress 3.3.1 is available for download Enlarge picture - WordPress 3.3.1 is available for download
A couple of Indian security researchers, Aditya Modha and Samir Shah, found an easy-to-exploit cross-site scripting (XSS) weakness that affected all WordPress 3.3 websites, but version 3.3.1 was quickly released to fix the issue.

The researchers showed that by posting a comment on a targeted site using a special script and by making sure the author, email and comment tags had the same values as the ones from the previous post they could generate a 500 internal server error.

The flaw works only on Internet Explorer browsers and Ethicalhack3r published a piece of code that prevents exploitation.

However, to make sure their websites are completely protected, users should update to the latest WordPress 3.3.1 as soon as possible.

The WordPress 3.3.1 maintenance release also fixes 15 functionality problems that affected WordPress 3.3.

WordPress 3.3.1
is available for download here.

TELL US WHAT YOU THINK:

1,636 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Microsoft Releases Security Update for DoS Issue in ASP.NET

Hashes Used by PHP, ASP.NET, Java, Python and Ruby Vulnerable to DoS Attacks

Microsoft Releases Out-of-Band Security Bulletin for ASP.NET/IIS on All Windows Versions

Simple Machines Forum Project Releases 2.0.2 and 1.1.16 Security Patches

Hackers Can Exploit WordPress 3.3 Sites by Posting Article Comments

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM