Wordpress Users, Beware - New Vulnerability Release

Milworm has announced a new exploit for the Wordpress Plugin, WP-Filemanager 1.2. The hole lets attackers upload pretty much anything they want, including evil PHP scripts.

For the details, check out: http://www.milw0rm.com/exploits/4844

If you don’t use the WP-Filemanager plugin and your Wordpress installation is current, don’t worry, you’re in the clear. Otherwise, I highly recommend you uninstall the plugin all together, or j00r b0x will get pwned. It’s times like this when I feel sorry for people with shared hosting accounts. Your site could fall victim to an attack because of some moron’s inability to keep their site secure.

Please note, the exploit was released today, so there’s still time, maybe. If you run WP-Filemanager 1.2, fix it now.

In addition, the following exploits were released and are available on Milworm’s web-site:

  • PortalApp 4.0 (SQL/XSS/Auth Bypasses) Multiple Remote Vulnerabilities
  • XOOPS mod_gallery Zend_Hash_key + Extract RFI Vulnerability
  • Uebimiau Web-Mail Remote File Disclosure Vulnerability
  • RunCMS Newbb_plus <= 0.92 Client IP Remote SQL Injection Exploit
  • MODx CMS 0.9.6.1 Multiple Remote Vulnerabilities

Ahhh, what a great way to bring in the new year.

Additional Posts Worth Reading

 

Comments »

No comments yet.

Name (required)


E-mail (required - never shown publicly)


URI - Web Site Address






Subscribe

Site of The Day

Sponsors

Categories

Recent Comments

  • Arthur: I can’t even be an Ebay affiliate. Tried various ways but still declined. Any help or suggestions?
  • chicago web design: I can’t imagine that these will last very long before Google banishes them all. But for now...
  • D.Ksyte: Anyone involved with cron job scheduling might find this resource useful. Cron Sandbox at HxPI is an...
  • FoNiX: “…decode md5″ is not possible, only bruteforce: generate hash and compare with original.
  • Z@$#: plz plz decript this hash for me any one….its really important…. 2CAD28C7C619F27DDE7B83C4999795BA
  • Joe: Thanks for writing this up. I tried the second method…however after the debian install the screen looks...
  • Scott: Was this issue ever resolved? I just started having a problem a couple weeks ago. I don’t do any kind of...
  • Prashant Patel: I had integrated Sp3 in Xp But finding one problem. In the Task Manager Process windows many services...
  • Ed: This looks like a real ‘leet’ linux command but it misses the point. Why would a hacker keep the name of...
  • Sudesh: My account was disabled but I followed their guideline and in one sec it was back on :) Here is the...

Top Commentators

Miscellaneous

  • Add to Technorati Favorites