Welcome guest, is this your first visit? Create Account now to join.
  • Login:

Members in Chat:
+ Reply to Thread
Page 2 of 2 FirstFirst 12
Results 11 to 16 of 16
  1. #11
    Join Date
    Dec 2008
    Location
    Minneapolis
    Posts
    529
    $NetBucks
    1,740
    Thanked 75 Times in 53 Posts
    This is what my blog looks like:

    $charset = $_POST['charset'];

    if(strlen($charset) > 50)
    die;

    // These three are stripslashed here so that they can be properly escaped after

    Quote Originally Posted by Snak3 View Post
    @nux
    can you show where exactly in wp-trackback.php have we to paste the following code as mentioned by you in your blog post :
    Code:
    if(strlen($charset) > 50)
    die;
    I understand line 47 but to be precise
    I mean, before what and after what piece of code should it come/appear.
    Submit Your Proxies @ Proxy Sites.net

  2. Thanked by:

    Snak3 (20 October, 2009)

  3. #12
    Join Date
    Mar 2009
    Posts
    262
    $NetBucks
    981
    Thanked 56 Times in 46 Posts
    Should we just remove the trackback.php file from the wordpress folder? Or rename it so its not usable until a full patch is released?

  4. #13
    Join Date
    Dec 2008
    Location
    Minneapolis
    Posts
    529
    $NetBucks
    1,740
    Thanked 75 Times in 53 Posts
    The code I showed you will fix the problem. I've tested it myself.
    Submit Your Proxies @ Proxy Sites.net

  5. #14
    Snak3's Avatar
    Snak3 is offline Moderator Recent Blog: Empathy
    Join Date
    Jul 2009
    Location
    Undisclosed Location
    Posts
    629
    $NetBucks
    2,072
    Thanked 189 Times in 121 Posts
    Quote Originally Posted by nux View Post
    This is what my blog looks like:

    $charset = $_POST['charset'];

    if(strlen($charset) > 50)
    die;

    // These three are stripslashed here so that they can be properly escaped after
    Thnx a bunch, done on my WP blog

  6. #15
    Join Date
    Dec 2008
    Location
    Minneapolis
    Posts
    529
    $NetBucks
    1,740
    Thanked 75 Times in 53 Posts
    Wordpress has released an update, 2.8.5 which fixes this issue.
    Submit Your Proxies @ Proxy Sites.net

  7. Thanked by:

    dmi (21 October, 2009), jayant_me (21 October, 2009)

  8. #16
    Join Date
    Dec 2008
    Posts
    143
    $NetBucks
    409
    Thanked 9 Times in 8 Posts
    just download and installed 2.8.5

    Thanks for the heads up


 

Similar Threads

  1. Replies: 19
    Last Post: 9 July, 2011, 07:44 AM
  2. Replies: 0
    Last Post: 1 December, 2009, 16:30 PM
  3. Fix Proxy Listing Exploit
    By chetan in forum Web Proxies
    Replies: 24
    Last Post: 25 September, 2009, 19:34 PM
  4. iPhone Exploit Exposed at Black Hat
    By m42 in forum Tech-Talk
    Replies: 5
    Last Post: 1 August, 2009, 13:03 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts