<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: 2 vanilla XSS on Wordpress &#8216;wp-register.php&#8217;</title>
	<atom:link href="http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: MustLive</title>
		<link>http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/comment-page-1#comment-4070</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Sun, 28 Oct 2007 15:29:36 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/#comment-4070</guid>
		<description>David, as I just found, you have restrictions in your comments. You are fun guy with fun site. When posting a comment I found that you have some limits with comment&#039;s text. It&#039;s possible or some bug in engine or some incorrect settings - because it&#039;s unserious settings, I can&#039;t post even a small message :-). You need to fix it. And take care about your site and its comments, so every part of site will work correctly.

About my holes in WP. Besides a lot of holes in WP plugins, I also have some holes in WordPress (in main WP bundle). Some holes concerning old WP versions (and possible new) with some requirements, and one hole concern possible all version of WP (including last). With this hole it&#039;s possible to hack every WP site (it&#039;s mega hole). This vuln is tricky to use, but can hack possibly all WP sites (it has some requirements, but they can be achieved and even improved with using some previous holes). With this complex attack every site on WP is in danger. Using WordPress is like a sitting on mine. So take care of your sites. The disclosure will in future. After November, which will the very hot month.</description>
		<content:encoded><![CDATA[<p>David, as I just found, you have restrictions in your comments. You are fun guy with fun site. When posting a comment I found that you have some limits with comment&#8217;s text. It&#8217;s possible or some bug in engine or some incorrect settings &#8211; because it&#8217;s unserious settings, I can&#8217;t post even a small message :-). You need to fix it. And take care about your site and its comments, so every part of site will work correctly.</p>
<p>About my holes in WP. Besides a lot of holes in WP plugins, I also have some holes in WordPress (in main WP bundle). Some holes concerning old WP versions (and possible new) with some requirements, and one hole concern possible all version of WP (including last). With this hole it&#8217;s possible to hack every WP site (it&#8217;s mega hole). This vuln is tricky to use, but can hack possibly all WP sites (it has some requirements, but they can be achieved and even improved with using some previous holes). With this complex attack every site on WP is in danger. Using WordPress is like a sitting on mine. So take care of your sites. The disclosure will in future. After November, which will the very hot month.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Philipp</title>
		<link>http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/comment-page-1#comment-1553</link>
		<dc:creator>Philipp</dc:creator>
		<pubDate>Thu, 04 Oct 2007 21:08:27 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/#comment-1553</guid>
		<description>@MustLive, thanks for letting us know. But one major Problem of the Internet is, that there&#039;s no central place for Disclosures or anything else. Many people try to get into some spotlight with their Service...
And please forgive us that we can&#039;t check all Disclosure Websites for already published disclosures. Especially none out of our language knowledge, And as we didn&#039;t found anything on Wordpress we supposed that flaw to be unknown, or silently fixed.
We&#039;re planning to do something like a Month of Wordpress Bugs(although for Plugins), so If you like we could do some joint venture.</description>
		<content:encoded><![CDATA[<p>@MustLive, thanks for letting us know. But one major Problem of the Internet is, that there&#8217;s no central place for Disclosures or anything else. Many people try to get into some spotlight with their Service&#8230;<br />
And please forgive us that we can&#8217;t check all Disclosure Websites for already published disclosures. Especially none out of our language knowledge, And as we didn&#8217;t found anything on Wordpress we supposed that flaw to be unknown, or silently fixed.<br />
We&#8217;re planning to do something like a Month of Wordpress Bugs(although for Plugins), so If you like we could do some joint venture.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Kierznowski</title>
		<link>http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/comment-page-1#comment-1552</link>
		<dc:creator>David Kierznowski</dc:creator>
		<pubDate>Thu, 04 Oct 2007 21:04:00 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/#comment-1552</guid>
		<description>MustLive, thanks for letting us know. If you want to do joint-releases with BlogSecurity regarding any of your future findings let us know man. Nice work.</description>
		<content:encoded><![CDATA[<p>MustLive, thanks for letting us know. If you want to do joint-releases with BlogSecurity regarding any of your future findings let us know man. Nice work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MustLive</title>
		<link>http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/comment-page-1#comment-1550</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Thu, 04 Oct 2007 20:50:23 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/#comment-1550</guid>
		<description>Guys.

From those holes that I found in WordPress, there is also one such XSS holes, besides these XSS holes in wp-register.php, which I found in WordPress MultiUser (and it&#039;s similar hole). It may be interesting for you.

As I wrote at my site http://websecurity.com.ua/1269/ - the hole (which I found at 06.11.2006) is in WordPress MultiUser 1.0 (and below). XSS is in wp-newblog.php script in Username field. And as I tested in WP MU 1.1.1 this hole was fixed.

About these holes in WP and WP MU I didn&#039;t inform WP developers (just disclosed at my site), because had not time for that and the holes was already fixed at time when I posted about them. But I planning to write about these holes to developers (to make them aware about a lot holes in their software - like I regularly inform them about holes in WP).

P.S.

There are some interesting holes in WP, which I found in June 2007 (and holes in some WP plugins which I found in 2006) which I planned to disclose in near future. And I&#039;ll inform developers. Just wait until time will come. Take care about your WP sites.</description>
		<content:encoded><![CDATA[<p>Guys.</p>
<p>From those holes that I found in WordPress, there is also one such XSS holes, besides these XSS holes in wp-register.php, which I found in WordPress MultiUser (and it&#8217;s similar hole). It may be interesting for you.</p>
<p>As I wrote at my site <a href="http://websecurity.com.ua/1269/" rel="nofollow">http://websecurity.com.ua/1269/</a> &#8211; the hole (which I found at 06.11.2006) is in WordPress MultiUser 1.0 (and below). XSS is in wp-newblog.php script in Username field. And as I tested in WP MU 1.1.1 this hole was fixed.</p>
<p>About these holes in WP and WP MU I didn&#8217;t inform WP developers (just disclosed at my site), because had not time for that and the holes was already fixed at time when I posted about them. But I planning to write about these holes to developers (to make them aware about a lot holes in their software &#8211; like I regularly inform them about holes in WP).</p>
<p>P.S.</p>
<p>There are some interesting holes in WP, which I found in June 2007 (and holes in some WP plugins which I found in 2006) which I planned to disclose in near future. And I&#8217;ll inform developers. Just wait until time will come. Take care about your WP sites.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BlogSecurity &#187; WordPress BlogWatch</title>
		<link>http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/comment-page-1#comment-1301</link>
		<dc:creator>BlogSecurity &#187; WordPress BlogWatch</dc:creator>
		<pubDate>Tue, 25 Sep 2007 17:25:27 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/#comment-1301</guid>
		<description>[...] wp_register XSS through user_email parameter (more) [...]</description>
		<content:encoded><![CDATA[<p>[...] wp_register XSS through user_email parameter (more) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/comment-page-1#comment-1255</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Sun, 23 Sep 2007 17:39:48 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/#comment-1255</guid>
		<description>Daniel,

Although WP is a great product functionality wise, security is &lt;i&gt;not&lt;/i&gt; a priority for the developers of the project (IMO).</description>
		<content:encoded><![CDATA[<p>Daniel,</p>
<p>Although WP is a great product functionality wise, security is <i>not</i> a priority for the developers of the project (IMO).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/comment-page-1#comment-1251</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Sun, 23 Sep 2007 12:44:13 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/#comment-1251</guid>
		<description>It&#039;s disgusting that this kind of vulnerability even existed in the first place.

Is it me or do WP developers just not give a shit about security?</description>
		<content:encoded><![CDATA[<p>It&#8217;s disgusting that this kind of vulnerability even existed in the first place.</p>
<p>Is it me or do WP developers just not give a shit about security?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Kierznowski</title>
		<link>http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/comment-page-1#comment-1220</link>
		<dc:creator>David Kierznowski</dc:creator>
		<pubDate>Sat, 22 Sep 2007 02:05:05 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/#comment-1220</guid>
		<description>No worries, late night brain power :)</description>
		<content:encoded><![CDATA[<p>No worries, late night brain power :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/comment-page-1#comment-1217</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Fri, 21 Sep 2007 23:14:00 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/#comment-1217</guid>
		<description>David,

Just wanted to make sure you typed what you meant. I know it&#039;s late on a Friday, so it&#039;s easy to make typos :-D</description>
		<content:encoded><![CDATA[<p>David,</p>
<p>Just wanted to make sure you typed what you meant. I know it&#8217;s late on a Friday, so it&#8217;s easy to make typos :-D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/comment-page-1#comment-1216</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Fri, 21 Sep 2007 23:12:30 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/#comment-1216</guid>
		<description>FYI,

just tested it on 1.5.1.1 and it IS vulnerable as well.</description>
		<content:encoded><![CDATA[<p>FYI,</p>
<p>just tested it on 1.5.1.1 and it IS vulnerable as well.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
