#4322 closed defect (bug) (fixed)
Sql injection blind fishing exploit
| Reported by: | DrHallows | Owned by: | |
|---|---|---|---|
| Priority: | highest omg bbq | Milestone: | 2.0.11 |
| Component: | Security | Version: | 2.1.3 |
| Severity: | critical | Keywords: | security, bug |
| Cc: | Focuses: |
Description
BIG security bug in "admin-ajax.php" sql injection blind fishing exploit
More info on: http://www.waraxe.us/ftopict-1780.html#7560
Attachments (1)
Change History (5)
#1
@
19 years ago
- Keywords security added; securtiy removed
- Milestone 2.2.1 → 2.0.11
- Resolution → fixed
- Status new → closed
#2
follow-up:
↓ 3
@
19 years ago
- Resolution fixed
- Status closed → reopened
According to this page:
"None of these are safe to use, except the latest in the 2.0 or 2.1 series, which are both actively maintained."
However version 2.1.3 is still not patched for this bug?
#3
in reply to: ↑ 2
@
19 years ago
- Resolution → fixed
- Status reopened → closed
Replying to hvdkamer:
According to this page:
"None of these are safe to use, except the latest in the 2.0 or 2.1 series, which are both actively maintained."
However version 2.1.3 is still not patched for this bug?
2.1.3 will not be patched.
The only security supported versions are 2.0.x and 2.2.x
This fix is in 2.2.1 which has just gone RC.
![(please configure the [header_logo] section in trac.ini)](/chrome/site/your_project_logo.png)
Fixed for 2.2, 2.0.11 (soon to be released) and in trunk for 2.3
[5440]
[5441]
[5442]