<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Wordpress 2.3.1 Charset SQL Injection Vulnerability</title>
	<atom:link href="http://blogsecurity.net/wordpress/wordpress-231-charset-sql-injection-vulnerability/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/wordpress/wordpress-231-charset-sql-injection-vulnerability</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: BlogSecurity &#187; Blog Archive &#187; WordPress Insecure by Design?</title>
		<link>http://blogsecurity.net/wordpress/wordpress-231-charset-sql-injection-vulnerability/comment-page-1#comment-6550</link>
		<dc:creator>BlogSecurity &#187; Blog Archive &#187; WordPress Insecure by Design?</dc:creator>
		<pubDate>Tue, 22 Jan 2008 20:47:16 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-231-charset-sql-injection-vulnerability/#comment-6550</guid>
		<description>[...] security and exploit a UTF-7 SQL Injection exploit some time ago. Another example of this, was Abel Cheung&#8217;s Charset SQL Injection vulnerability, published last month (which in theory should still be [...]</description>
		<content:encoded><![CDATA[<p>[...] security and exploit a UTF-7 SQL Injection exploit some time ago. Another example of this, was Abel Cheung&#8217;s Charset SQL Injection vulnerability, published last month (which in theory should still be [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wordpress 2.3.1 Charset SQL Injection Vulnerability &#124; MySQL Security</title>
		<link>http://blogsecurity.net/wordpress/wordpress-231-charset-sql-injection-vulnerability/comment-page-1#comment-6113</link>
		<dc:creator>Wordpress 2.3.1 Charset SQL Injection Vulnerability &#124; MySQL Security</dc:creator>
		<pubDate>Wed, 12 Dec 2007 06:55:23 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-231-charset-sql-injection-vulnerability/#comment-6113</guid>
		<description>[...] more from the original source: Wordpress 2.3.1 Charset SQL Injection Vulnerability ftp securityftp securityRelated Posts [waraxe-2007-SA#059] - XSS in WordPress [...]</description>
		<content:encoded><![CDATA[<p>[...] more from the original source: Wordpress 2.3.1 Charset SQL Injection Vulnerability ftp securityftp securityRelated Posts [waraxe-2007-SA#059] &#8211; XSS in WordPress [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Abel Cheung</title>
		<link>http://blogsecurity.net/wordpress/wordpress-231-charset-sql-injection-vulnerability/comment-page-1#comment-6107</link>
		<dc:creator>Abel Cheung</dc:creator>
		<pubDate>Tue, 11 Dec 2007 20:08:22 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-231-charset-sql-injection-vulnerability/#comment-6107</guid>
		<description>My stupidity. Although I originally intend to say removing the function entirely, it was written in such bad way that, the meaning end up like what Flo said. Will update advisory soon.</description>
		<content:encoded><![CDATA[<p>My stupidity. Although I originally intend to say removing the function entirely, it was written in such bad way that, the meaning end up like what Flo said. Will update advisory soon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Philipp</title>
		<link>http://blogsecurity.net/wordpress/wordpress-231-charset-sql-injection-vulnerability/comment-page-1#comment-6105</link>
		<dc:creator>Philipp</dc:creator>
		<pubDate>Tue, 11 Dec 2007 19:00:59 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-231-charset-sql-injection-vulnerability/#comment-6105</guid>
		<description>I can&#039;t talk for Abel, but mostly I believe he&#039;s aiming at removing it in such a way that it&#039;s not working at all anymore(although no direct link to it)</description>
		<content:encoded><![CDATA[<p>I can&#8217;t talk for Abel, but mostly I believe he&#8217;s aiming at removing it in such a way that it&#8217;s not working at all anymore(although no direct link to it)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Flo</title>
		<link>http://blogsecurity.net/wordpress/wordpress-231-charset-sql-injection-vulnerability/comment-page-1#comment-6103</link>
		<dc:creator>Flo</dc:creator>
		<pubDate>Tue, 11 Dec 2007 18:44:26 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-231-charset-sql-injection-vulnerability/#comment-6103</guid>
		<description>I doubt that removing search from the theme would help much. One could still trigger the search (and therefore the exploit) over the URL, even if no results were shown.</description>
		<content:encoded><![CDATA[<p>I doubt that removing search from the theme would help much. One could still trigger the search (and therefore the exploit) over the URL, even if no results were shown.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

