PHP XML-RPC Vulnerability

Jul 5

PHP XML-RPC Vulnerability

PHP Blogging Apps Vulnerable to XML-RPC Exploits: This is very, very bad.

Many popular PHP-based blogging, wiki and content management programs can be exploited through a security hole in the way PHP programs handle XML commands. The flaw allows an attacker to compromise a web server, and is found in programs including PostNuke, WordPress, Drupal, Serendipity, phpAdsNew, phpWiki and phpMyFAQ, among others.

[…] By creating an XML file that uses single quotes to escape into the eval() call an attacker can easily execute php code on the target server.

Ouch.


Comments

by Glenn,   July 6, 2005 12:27 AM  

Actually, Wordpress is fine (see Matt)



Comments are Closed

Thanks to all who participated.

Want to advertise on this site? Contact FM.