MalwareTeks Blog » Blog Archive » WordPress 2.1.1 Users at Risk


 04 Mar 2007 @ 10:40 AM 
 

WordPress 2.1.1 Users at Risk

 

Somebody managed to hack into the Wordpress server and modified two files in WordPress v2.1.1 to include code that would allow for remote PHP execution. Although not all downloads of v2.1.1 were affected, WordPress.org has declared the entire version dangerous and has released version 2.1.2 that includes minor updates and entirely verified files.

WordPress Article: WordPress 2.1.1 Dangerous, Upgrade

EDIT (4 March 7:28 PM): WordPress reports that the v2.1.2 code base is clean and in fact the below code is included by the developers in all copies of index.php in the WordPress package.

EDIT: It would appear that someone has successfully hacked Version 2.1.2 and has modified index.php

<?php
// Silence is golden.
?>

STATEMENT REMOVED ~ SPD ~

Reference: Wordpress 2.1.2 download package hacked

Share our articles with others by publishing them to:
  • Digg
  • Reddit
  • del.icio.us
  • Slashdot
  • StumbleUpon
  • Technorati
  • blogmarks
  • Furl
  • YahooMyWeb
  • Fark
Tags Tags:
Categories: Uncategorized
Posted By: ShadowPuterDude
Last Edit: 04 Mar 2007 @ 07 34 PM
691 views
E-mailPermalink
 

Responses to this post » (None)

 


Comments are open. Feel free to leave a comment below.


 

Leave A Comment ...

 

 XHTML:
You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
\/ More Options ...
Change Theme...
  • Users » 9
  • Posts/Pages » 187
  • Comments » 116
Change Theme...
  • VoidVoid « Default
  • LifeLife
  • EarthEarth
  • WindWind
  • WaterWater
  • FireFire
  • LiteLight
  • No Child Pages.
  • No Child Pages.
  • No Child Pages.
  • No Child Pages.
  • No Child Pages.
  • No Child Pages.