Bug#504771: wordpress can be subject of delayed attacks via cookies

2008-11-07 Thread Raphael Geissert
2008/11/7 Andrea De Iacovo <[EMAIL PROTECTED]>: >> Package: wordpress >> Version: 2.0.7-1 >> Severity: grave >> Tags: security >> >> Hi, >> >> Due to the completely incorrect usage of $_REQUEST almost all over the place >> wordpress is subject to delayed attacks via cookies. >> >> The attack can be

Bug#504771: wordpress can be subject of delayed attacks via cookies

2008-11-07 Thread Andrea De Iacovo
> Package: wordpress > Version: 2.0.7-1 > Severity: grave > Tags: security > > Hi, > > Due to the completely incorrect usage of $_REQUEST almost all over the place > wordpress is subject to delayed attacks via cookies. > > The attack can be performed as long as there is some way to inject a coo

Bug#504771: wordpress can be subject of delayed attacks via cookies

2008-11-06 Thread Raphael Geissert
Package: wordpress Version: 2.0.7-1 Severity: grave Tags: security Hi, Due to the completely incorrect usage of $_REQUEST almost all over the place wordpress is subject to delayed attacks via cookies. The attack can be performed as long as there is some way to inject a cookie which is sent by