<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Wordpress 2.3: edit-post-rows XSS Vulnerability</title>
	<atom:link href="http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: WordPress 2.3 e suas Falhas de Segurança &#124; Vomicae™</title>
		<link>http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability/comment-page-1#comment-4403</link>
		<dc:creator>WordPress 2.3 e suas Falhas de Segurança &#124; Vomicae™</dc:creator>
		<pubDate>Sun, 04 Nov 2007 14:04:29 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability/#comment-4403</guid>
		<description>[...] blogroll spam on Wordpress 2.3 Wordpress 2.3: edit-post-rows XSS Vulnerability Post Relacionados:XHTML Válido para Vídeos: Youtube, Google, MySpace e Metacafe no Wordpress em [...]</description>
		<content:encoded><![CDATA[<p>[...] blogroll spam on Wordpress 2.3 Wordpress 2.3: edit-post-rows XSS Vulnerability Post Relacionados:XHTML Válido para Vídeos: Youtube, Google, MySpace e Metacafe no Wordpress em [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michas Blog &#124; XSS-Sicherheitslücke in Wordpress 2.3</title>
		<link>http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability/comment-page-1#comment-4270</link>
		<dc:creator>Michas Blog &#124; XSS-Sicherheitslücke in Wordpress 2.3</dc:creator>
		<pubDate>Thu, 01 Nov 2007 08:48:56 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability/#comment-4270</guid>
		<description>[...] gewagt hat, sollte jetzt das Update auf Version 2.3.1 starten. Dort gibt es ein paar Bugfixes und eine XSS - Lücke die geschlossen wird. Ich hab das Update diese Woche bereits ohne Probleme [...]</description>
		<content:encoded><![CDATA[<p>[...] gewagt hat, sollte jetzt das Update auf Version 2.3.1 starten. Dort gibt es ein paar Bugfixes und eine XSS &#8211; Lücke die geschlossen wird. Ich hab das Update diese Woche bereits ohne Probleme [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SigT</title>
		<link>http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability/comment-page-1#comment-4238</link>
		<dc:creator>SigT</dc:creator>
		<pubDate>Wed, 31 Oct 2007 14:07:24 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability/#comment-4238</guid>
		<description>&lt;strong&gt;Vulnerabilidad XSS &#8220;edit-post-rows&#8221; en WordPress 2.3...&lt;/strong&gt;

Si todavía usáis la versión 2.3 de WordPress toca actualizar a la última 2.3.1 ya que a la lista de fallos que han ido saliendo (uno de los más grave comentado por aquí) acaban de informar de otro fallo XSS.

En esta ocasión se trata de un fallo...</description>
		<content:encoded><![CDATA[<p><strong>Vulnerabilidad XSS &#8220;edit-post-rows&#8221; en WordPress 2.3&#8230;</strong></p>
<p>Si todavía usáis la versión 2.3 de WordPress toca actualizar a la última 2.3.1 ya que a la lista de fallos que han ido saliendo (uno de los más grave comentado por aquí) acaban de informar de otro fallo XSS.</p>
<p>En esta ocasión se trata de un fallo&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The OS Quest &#187; Security Quest #8 - Leopard Default Insecurity</title>
		<link>http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability/comment-page-1#comment-4216</link>
		<dc:creator>The OS Quest &#187; Security Quest #8 - Leopard Default Insecurity</dc:creator>
		<pubDate>Wed, 31 Oct 2007 05:27:29 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability/#comment-4216</guid>
		<description>[...] was a vulnerability announced in Wordpress 2.3. It&#8217;s resolved in 2.3.1 and doesn&#8217;t appear to exist in earlier [...]</description>
		<content:encoded><![CDATA[<p>[...] was a vulnerability announced in Wordpress 2.3. It&#8217;s resolved in 2.3.1 and doesn&#8217;t appear to exist in earlier [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: -=Discobeats=-</title>
		<link>http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability/comment-page-1#comment-4182</link>
		<dc:creator>-=Discobeats=-</dc:creator>
		<pubDate>Tue, 30 Oct 2007 09:15:32 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability/#comment-4182</guid>
		<description>&lt;strong&gt;[WordPress] XSS-Verwundbarkeit in 2.3...&lt;/strong&gt;



Laut Blog Security existiert eine XSS-L&#252;cke in WordPress 2.3
Diese L&#252;cke betrifft nur Webspaces mit register_global enabled und auch nur die Version 2.3. Die Versionen 2.2.3 oder die aktuelle Version 2.3.1 sind davon nicht betroffen.
Wieder...</description>
		<content:encoded><![CDATA[<p><strong>[WordPress] XSS-Verwundbarkeit in 2.3&#8230;</strong></p>
<p>Laut Blog Security existiert eine XSS-L&#252;cke in WordPress 2.3<br />
Diese L&#252;cke betrifft nur Webspaces mit register_global enabled und auch nur die Version 2.3. Die Versionen 2.2.3 oder die aktuelle Version 2.3.1 sind davon nicht betroffen.<br />
Wieder&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BlogSecurity &#187; Blog Archive &#187; WordPress BlogWatch</title>
		<link>http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability/comment-page-1#comment-4181</link>
		<dc:creator>BlogSecurity &#187; Blog Archive &#187; WordPress BlogWatch</dc:creator>
		<pubDate>Tue, 30 Oct 2007 08:56:21 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability/#comment-4181</guid>
		<description>[...] XSS injection in edit-post-rows.php, with register_globals on (More) [...]</description>
		<content:encoded><![CDATA[<p>[...] XSS injection in edit-post-rows.php, with register_globals on (More) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Kierznowski</title>
		<link>http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability/comment-page-1#comment-4176</link>
		<dc:creator>David Kierznowski</dc:creator>
		<pubDate>Tue, 30 Oct 2007 07:18:36 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability/#comment-4176</guid>
		<description>Thanks for the update Phil.</description>
		<content:encoded><![CDATA[<p>Thanks for the update Phil.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Philipp</title>
		<link>http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability/comment-page-1#comment-4174</link>
		<dc:creator>Philipp</dc:creator>
		<pubDate>Tue, 30 Oct 2007 06:56:39 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-23-edit-post-rows-xss-vulnerability/#comment-4174</guid>
		<description>This flaw affects only 2.3, within 2.3.1 it&#039;s fixed and below 2.3 the file wasn&#039;t there. Anyway I&#039;m not sure who discovered that flaw at all as&lt;a href=&quot;http://westi.wordpress.com/2007/10/26/wordpress-231-in-detail/&quot; rel=&quot;nofollow&quot;&gt;Peter Westwood&lt;/a&gt; covered that one already and I didn&#039;t found any Trac entry for that one. Maybe the developer got the attention to it, without any notice.</description>
		<content:encoded><![CDATA[<p>This flaw affects only 2.3, within 2.3.1 it&#8217;s fixed and below 2.3 the file wasn&#8217;t there. Anyway I&#8217;m not sure who discovered that flaw at all as<a href="http://westi.wordpress.com/2007/10/26/wordpress-231-in-detail/" rel="nofollow">Peter Westwood</a> covered that one already and I didn&#8217;t found any Trac entry for that one. Maybe the developer got the attention to it, without any notice.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

