WordPress Remote Command Execution
Saturday, June 3rd, 2006The SANS Institute has unconfirmed reports that all WordPress version (2.0.2 and prior) are vulnerable to a remote command execution vulnerability and an IP spoofing attack. By sending a specially-crafted request, an attacker can cause servers which open user registration or open account information modification to execute arbitrary commands with the privilege of the web [...]




