<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Top 10 Vulnerable WP Themes</title>
	<atom:link href="http://blogsecurity.net/wordpress/article-050807/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/wordpress/article-050807</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Webgazette.co.uk &#187; Blog Archive &#187; WordPress Theme Vulnerability Confusion</title>
		<link>http://blogsecurity.net/wordpress/article-050807/comment-page-1#comment-14470</link>
		<dc:creator>Webgazette.co.uk &#187; Blog Archive &#187; WordPress Theme Vulnerability Confusion</dc:creator>
		<pubDate>Sun, 16 Nov 2008 23:08:26 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/article-050807/#comment-14470</guid>
		<description>[...] was surprised to find WP-Multiflex-03 listed&#160;in the post&#160;&#8221;Top 10 Vulnerable WP Themes&#8220;on [...]</description>
		<content:encoded><![CDATA[<p>[...] was surprised to find WP-Multiflex-03 listed&nbsp;in the post&nbsp;&#8221;Top 10 Vulnerable WP Themes&#8220;on [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Philipp</title>
		<link>http://blogsecurity.net/wordpress/article-050807/comment-page-1#comment-12196</link>
		<dc:creator>Philipp</dc:creator>
		<pubDate>Mon, 21 Jul 2008 21:40:42 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/article-050807/#comment-12196</guid>
		<description>Hi Carla, I&#039;ve just checked the Changelog of the theme, and there are two Security issues reported to be closed, one is in the linked post mentioned search Cross Site Scripting Problem and the other one is mostly the problem about the PHP_SELF thing(mentioned in Adams Comment abit above). So it seems that this theme doesn&#039;t suffer under vulnerabilites, but we can&#039;t tell it for sure as we didn&#039;t made a full audit for it.
Just some late addition to Adams Post within the Changelog you find some weeks before your Post a entry about a possible security hole, mostly the mentioned problem by Adams comment. So this theme was indeed vulnerable when this post was created.</description>
		<content:encoded><![CDATA[<p>Hi Carla, I&#8217;ve just checked the Changelog of the theme, and there are two Security issues reported to be closed, one is in the linked post mentioned search Cross Site Scripting Problem and the other one is mostly the problem about the PHP_SELF thing(mentioned in Adams Comment abit above). So it seems that this theme doesn&#8217;t suffer under vulnerabilites, but we can&#8217;t tell it for sure as we didn&#8217;t made a full audit for it.<br />
Just some late addition to Adams Post within the Changelog you find some weeks before your Post a entry about a possible security hole, mostly the mentioned problem by Adams comment. So this theme was indeed vulnerable when this post was created.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: YSecure &#187; First Thing&#8217;s First - Make my Blog Pretty (and attack my visitors)</title>
		<link>http://blogsecurity.net/wordpress/article-050807/comment-page-1#comment-11929</link>
		<dc:creator>YSecure &#187; First Thing&#8217;s First - Make my Blog Pretty (and attack my visitors)</dc:creator>
		<pubDate>Sun, 06 Jul 2008 18:21:11 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/article-050807/#comment-11929</guid>
		<description>[...] hackers to add their pieces of code to your blog - and attack your visitors. There&#8217;s even a scanner for [...]</description>
		<content:encoded><![CDATA[<p>[...] hackers to add their pieces of code to your blog &#8211; and attack your visitors. There&#8217;s even a scanner for [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Carla</title>
		<link>http://blogsecurity.net/wordpress/article-050807/comment-page-1#comment-11928</link>
		<dc:creator>Carla</dc:creator>
		<pubDate>Sun, 06 Jul 2008 04:49:07 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/article-050807/#comment-11928</guid>
		<description>I&#039;ve built several blogs for clients lately using Tarski, because I found it so flexible. So my heart sunk when I saw that it was on your list. I don&#039;t know when the list was updated last, so I thought I&#039;d inquire whether you have any new information about vulnerabilities in the Tarski theme. OMG, I hope the versions I&#039;ve used are OK! 

Thanks for your help.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve built several blogs for clients lately using Tarski, because I found it so flexible. So my heart sunk when I saw that it was on your list. I don&#8217;t know when the list was updated last, so I thought I&#8217;d inquire whether you have any new information about vulnerabilities in the Tarski theme. OMG, I hope the versions I&#8217;ve used are OK! </p>
<p>Thanks for your help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: אבטחת וורדפרס &#187; ITbananas</title>
		<link>http://blogsecurity.net/wordpress/article-050807/comment-page-1#comment-11620</link>
		<dc:creator>אבטחת וורדפרס &#187; ITbananas</dc:creator>
		<pubDate>Wed, 18 Jun 2008 23:34:19 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/article-050807/#comment-11620</guid>
		<description>[...] שלתבנית שאנחנו משתמשים אין חורים באבטחה&#124; פלאגין: [...]</description>
		<content:encoded><![CDATA[<p>[...] שלתבנית שאנחנו משתמשים אין חורים באבטחה| פלאגין: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DK</title>
		<link>http://blogsecurity.net/wordpress/article-050807/comment-page-1#comment-4267</link>
		<dc:creator>DK</dc:creator>
		<pubDate>Thu, 01 Nov 2007 07:13:59 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/article-050807/#comment-4267</guid>
		<description>libel? :)

There was alot of controversy about this post, and at some point i&#039;ll release part 2. 

There is really nothing &quot;shoddy&quot; about it. The vulnerability&#039;s covered here are not just limited to PHP_SELF in the header.

If you&#039;d like to start hunting down theme authors be my guest - I hate to sound careless but I have better things to do with my time and most of them are aware of this post by now.</description>
		<content:encoded><![CDATA[<p>libel? :)</p>
<p>There was alot of controversy about this post, and at some point i&#8217;ll release part 2. </p>
<p>There is really nothing &quot;shoddy&quot; about it. The vulnerability&#8217;s covered here are not just limited to PHP_SELF in the header.</p>
<p>If you&#8217;d like to start hunting down theme authors be my guest &#8211; I hate to sound careless but I have better things to do with my time and most of them are aware of this post by now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: adam</title>
		<link>http://blogsecurity.net/wordpress/article-050807/comment-page-1#comment-4237</link>
		<dc:creator>adam</dc:creator>
		<pubDate>Wed, 31 Oct 2007 14:05:40 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/article-050807/#comment-4237</guid>
		<description>i&#039;m still baffled by this list.  it seems like horribly shoddy research on your part, and possibly libel, to suggest that these themes are vulnerable, to not do the due dilligence to find out if they&#039;ve been updated, or to contact the authors before listing their themes.  

tarski, for instance, like most themes, uses &lt;code&gt;get_bloginfo()&lt;/code&gt;, rather than &lt;code&gt;$_SERVER[&#039;PHP_SELF&#039;]&lt;/code&gt;.</description>
		<content:encoded><![CDATA[<p>i&#8217;m still baffled by this list.  it seems like horribly shoddy research on your part, and possibly libel, to suggest that these themes are vulnerable, to not do the due dilligence to find out if they&#8217;ve been updated, or to contact the authors before listing their themes.  </p>
<p>tarski, for instance, like most themes, uses <code>get_bloginfo()</code>, rather than <code>$_SERVER['PHP_SELF']</code>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blackcell.com &#187; Top 10 Vulnerable Wordpress Themes</title>
		<link>http://blogsecurity.net/wordpress/article-050807/comment-page-1#comment-681</link>
		<dc:creator>Blackcell.com &#187; Top 10 Vulnerable Wordpress Themes</dc:creator>
		<pubDate>Sun, 12 Aug 2007 23:32:11 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/article-050807/#comment-681</guid>
		<description>[...] For More Information visit http://blogsecurity.net/wordpress/article-050807/ [...]</description>
		<content:encoded><![CDATA[<p>[...] For More Information visit <a href="http://blogsecurity.net/wordpress/article-050807/" rel="nofollow">http://blogsecurity.net/wordpress/article-050807/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 5 Things You Can Do To Make Your Blog Safer From Hackers* :: 2k Bloggers - The Face of the Blogosphere</title>
		<link>http://blogsecurity.net/wordpress/article-050807/comment-page-1#comment-673</link>
		<dc:creator>5 Things You Can Do To Make Your Blog Safer From Hackers* :: 2k Bloggers - The Face of the Blogosphere</dc:creator>
		<pubDate>Sun, 12 Aug 2007 14:44:45 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/article-050807/#comment-673</guid>
		<description>[...] Update your blogware if you host your own blog. That means, use the newest version of WordPress. Make sure your blog&#8217;s theme is up-to-date and secure as well. Don&#8217;t use these themes. [...]</description>
		<content:encoded><![CDATA[<p>[...] Update your blogware if you host your own blog. That means, use the newest version of WordPress. Make sure your blog&#8217;s theme is up-to-date and secure as well. Don&#8217;t use these themes. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Security</title>
		<link>http://blogsecurity.net/wordpress/article-050807/comment-page-1#comment-652</link>
		<dc:creator>WordPress Security</dc:creator>
		<pubDate>Fri, 10 Aug 2007 18:28:25 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/article-050807/#comment-652</guid>
		<description>[...] A Top10-List of vulnerable themes [...]</description>
		<content:encoded><![CDATA[<p>[...] A Top10-List of vulnerable themes [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
