• Skip to main content

Audit My PC - Free Internet Security Audit

Firewall Test and web tools to check your security and privacy

  • Firewall Test
  • Anti Spam
  • Internet Speed Test
  • Sitemap Generator
  • Whats My IP

WordPress User Profile Cache Injection Arbitrary PHP Code Injection

Network Security News – Thursday, June 08, 2006 Events

WordPress User Profile Cache Injection Arbitrary PHP Code Injection

WordPress contains a flaw that may allow a malicious user to compromise a vulnerable system. The issue is triggered due to a lack of proper sanitization of various fields when registering or updating the user profile before being stored in PHP scripts in the wp-content/cache/userlogins/ and wp-content/cache/users/ directories inside the web root. It is possible that the flaw may allow an attacker to inject and execute arbitrary PHP code via the newline character resulting in a loss of integrity.. Read more at osvdb.org/25777

WordPress PC_REMOTE_ADDR vars.php IP Spoofing

WordPress contains a flaw that may allow a malicious user to spoof their IP address. The issue is triggered when an attacker registers with a specially crafted request with the PC_REMOTE_ADDR HTTP header set. It is possible that the flaw may allow a remote attacker to bypass IP based access restrictions resulting in a loss of integrity.. Read more at osvdb.org/25935

Copyright © 2001-2024 Audit My PC .com All Rights Reserved. Our Privacy Policy and TOS

  • About