<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress 2.3.1 SQL Injection Vulnerability</title>
	<atom:link href="http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Vladimir</title>
		<link>http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/comment-page-1#comment-11599</link>
		<dc:creator>Vladimir</dc:creator>
		<pubDate>Mon, 16 Jun 2008 06:20:37 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/#comment-11599</guid>
		<description>Actually, this &quot;hack&quot; allows to gather enough information to launch another attack and gain admin privileges :-) For 2.3.x branch.

Sorry, I won&#039;t publish details.</description>
		<content:encoded><![CDATA[<p>Actually, this &#8220;hack&#8221; allows to gather enough information to launch another attack and gain admin privileges :-) For 2.3.x branch.</p>
<p>Sorry, I won&#8217;t publish details.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nueva Vulnerabilidad en Wordpress &#171; Celciuz&#8217;s Weblog</title>
		<link>http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/comment-page-1#comment-6281</link>
		<dc:creator>Nueva Vulnerabilidad en Wordpress &#171; Celciuz&#8217;s Weblog</dc:creator>
		<pubDate>Wed, 02 Jan 2008 01:12:37 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/#comment-6281</guid>
		<description>[...] otherz: Remote SQL inyection on Wordpress 2.3.1  [...]</description>
		<content:encoded><![CDATA[<p>[...] otherz: Remote SQL inyection on Wordpress 2.3.1  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#160; &#160; WordPress 2.3.2 推出&#160;by&#160;BloggingPro China</title>
		<link>http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/comment-page-1#comment-6268</link>
		<dc:creator>&#160; &#160; WordPress 2.3.2 推出&#160;by&#160;BloggingPro China</dc:creator>
		<pubDate>Mon, 31 Dec 2007 03:53:58 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/#comment-6268</guid>
		<description>[...] btw: 很早前我就看到了 WP 2.3.1 SQL 注入的漏洞，并且测试了几个 Blog 确实管用 -_-b。考虑到安全问题，没有报道。现在有了解决办法，说出来也无妨了。如果您需要了解细节，转向到这里来看 [...]</description>
		<content:encoded><![CDATA[<p>[...] btw: 很早前我就看到了 WP 2.3.1 SQL 注入的漏洞，并且测试了几个 Blog 确实管用 -_-b。考虑到安全问题，没有报道。现在有了解决办法，说出来也无妨了。如果您需要了解细节，转向到这里来看 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Urgent Security Update to Wordpress &#171; Zit Seng&#8217;s Superwall</title>
		<link>http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/comment-page-1#comment-6262</link>
		<dc:creator>Urgent Security Update to Wordpress &#171; Zit Seng&#8217;s Superwall</dc:creator>
		<pubDate>Sun, 30 Dec 2007 04:41:27 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/#comment-6262</guid>
		<description>[...] necessitated an urgent security release. Wordpress 2.3.2 is now available. One of the problem is a SQL Injection Vulnerability that exposes internal information about your Wordpress installation. These are common problems that [...]</description>
		<content:encoded><![CDATA[<p>[...] necessitated an urgent security release. Wordpress 2.3.2 is now available. One of the problem is a SQL Injection Vulnerability that exposes internal information about your Wordpress installation. These are common problems that [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Wednesday News: WordPress Theme Viewer Waits, New Social Network, Security Issues, Austin Grows, Gravatars Enabled, WordPress Books, Matt Cutts, and More : The Blog Herald</title>
		<link>http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/comment-page-1#comment-6126</link>
		<dc:creator>WordPress Wednesday News: WordPress Theme Viewer Waits, New Social Network, Security Issues, Austin Grows, Gravatars Enabled, WordPress Books, Matt Cutts, and More : The Blog Herald</dc:creator>
		<pubDate>Thu, 13 Dec 2007 04:15:33 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/#comment-6126</guid>
		<description>[...] Blog Security - WordPress information disclosure vulnerability [...]</description>
		<content:encoded><![CDATA[<p>[...] Blog Security &#8211; WordPress information disclosure vulnerability [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BlogSecurity &#187; Blog Archive &#187; wpdberrors plugin: removing WordPress DB errors</title>
		<link>http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/comment-page-1#comment-6098</link>
		<dc:creator>BlogSecurity &#187; Blog Archive &#187; wpdberrors plugin: removing WordPress DB errors</dc:creator>
		<pubDate>Tue, 11 Dec 2007 13:40:08 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/#comment-6098</guid>
		<description>[...] recent WordPress information disclosure vulnerability demonstrates the potential dangers of having these error messages displayed to the user. It leaks [...]</description>
		<content:encoded><![CDATA[<p>[...] recent WordPress information disclosure vulnerability demonstrates the potential dangers of having these error messages displayed to the user. It leaks [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ozh</title>
		<link>http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/comment-page-1#comment-6096</link>
		<dc:creator>Ozh</dc:creator>
		<pubDate>Tue, 11 Dec 2007 08:40:25 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/#comment-6096</guid>
		<description>Yet another &quot;OMG SQL HAX VULNERABILITY&quot; critical alert that I cannot reproduce on any of my blogs, running on different software combinations.

The sad thing is that everybody&#039;s relaying this information. The saddest thing is that the so called experts who found this bother as usual more about exposure than sharing their findings with developpers. This is pathetic.</description>
		<content:encoded><![CDATA[<p>Yet another &#8220;OMG SQL HAX VULNERABILITY&#8221; critical alert that I cannot reproduce on any of my blogs, running on different software combinations.</p>
<p>The sad thing is that everybody&#8217;s relaying this information. The saddest thing is that the so called experts who found this bother as usual more about exposure than sharing their findings with developpers. This is pathetic.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: blad3</title>
		<link>http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/comment-page-1#comment-6095</link>
		<dc:creator>blad3</dc:creator>
		<pubDate>Tue, 11 Dec 2007 08:39:44 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/#comment-6095</guid>
		<description>It would better to try to reproduce the vulnerability before posting it on your blog. A lot of lamers are posting crap on security lists without testing or even understanding what they found. Don&#039;t help them get more attention.</description>
		<content:encoded><![CDATA[<p>It would better to try to reproduce the vulnerability before posting it on your blog. A lot of lamers are posting crap on security lists without testing or even understanding what they found. Don&#8217;t help them get more attention.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Clark</title>
		<link>http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/comment-page-1#comment-6093</link>
		<dc:creator>Michael Clark</dc:creator>
		<pubDate>Mon, 10 Dec 2007 22:07:48 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/#comment-6093</guid>
		<description>I&#039;m unable to reproduce this as well. Maybe it only works on specific versions of MySQL.</description>
		<content:encoded><![CDATA[<p>I&#8217;m unable to reproduce this as well. Maybe it only works on specific versions of MySQL.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: blogator.de &#187; Blog Archive &#187; SQL Injection for WordPress 2.3.1</title>
		<link>http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/comment-page-1#comment-6092</link>
		<dc:creator>blogator.de &#187; Blog Archive &#187; SQL Injection for WordPress 2.3.1</dc:creator>
		<pubDate>Mon, 10 Dec 2007 21:58:50 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wordpress-231-sql-injection-vulnerability/#comment-6092</guid>
		<description>[...] ist mal wieder so weit. Es gibt eine SQL Injection. Aktuell soll es noch keinen Patch geben. Evtl. kann aber dieses hier helfen. Ansonsten hilft ein [...]</description>
		<content:encoded><![CDATA[<p>[...] ist mal wieder so weit. Es gibt eine SQL Injection. Aktuell soll es noch keinen Patch geben. Evtl. kann aber dieses hier helfen. Ansonsten hilft ein [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
