ThreatPress

WordPress Vulnerabilities Database

Back

WordPress <= 2.1.1 - Multiple Vulnerabilities

Product
WordPress
Description
The attackers can execute arbitrary commands via an eval injection vulnerability in the "ix" parameter to wp-includes/feed.php. Also, there is command execution backdoor vulnerability.
Solution
Update the WordPress to the latest available version (at least 2.1.2).
Classification
Type Multi
References
CVE Mitre
CVE
Name CVE-2007-1277
Versions
Affected In <= 2.1.1
Fixed In 2.1.2
Disclosure date
2007-03-05
Credits
Ivan Fratric
Submitter
ThreatPress