Make WordPress Core

Changes between Version 11 and Version 14 of Ticket #5313


Ignore:
Timestamp:
02/02/2008 05:45:20 PM (18 years ago)
Author:
lloydbudd
Comment:

Legend:

Unmodified
Added
Removed
Modified
  • Ticket #5313

    • Property Severity changed from critical to blocker
  • Ticket #5313 – Description

    v11 v14  
    33Feb 2, 2008 http://wordpress.org/support/topic/134928 now describes a security issue in xml-rpc:
    44
    5 A personal has to already have an account on your blog, or be able to create an account (subscription)
     5Although this ticket has been open for 3 months, the previous description and the discussion here, on the forums, and elsewhere did not identify the vector.
    66
    7 WORKAROUND: if enabled, disable subscription to your blog, or remove xmlrpc.php .
     7A person has to already have an account on your blog, or be able to create an account (even just subscription) to abuse this bug.
     8
     9WORKAROUND: if enabled, disable account creation including subscription to your blog, or temporarily delete the file xmlrpc.php .
    810
    911http://wordpress.org/support/topic/134928/page/2#post-686510