Four-year-old comment security bug affects 86 percent of WordPress sites (Ars Technica)
Four-year-old comment security bug affects 86 percent of WordPress sites (Ars Technica)
Posted Nov 25, 2014 20:30 UTC (Tue) by iabervon (subscriber, #722)In reply to: Four-year-old comment security bug affects 86 percent of WordPress sites (Ars Technica) by drag
Parent article: Four-year-old comment security bug affects 86 percent of WordPress sites (Ars Technica)
I was trying to think of situations where the attacker doesn't have to be a user on the vulnerable site (in order to get through your only-over-vpn or ssl auth defense). I could imagine a site you might run that only you can sync your phone to and only you can browse that data, but it could easily show id3v2 tags in your mp3s, and fail to strip the HTML in them, so that looking at a malicious mp3 might induce you to reconfigure the site. The fact that the attacker can't communicate at all with the site wouldn't save you in this situation.
The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:
Note: you can avoid this step in the future by logging into your LWN account.
