Re: WordPress possilbe SQL injections [was: SELinux - way of the future or good idea but !!!]

Leonard den Ottolander <leonard-2Avth2y2NeLyQNdsBcn8aGZHpeb/A1Y/@public.gmane.org>
Newsgroups gmane.linux.centos.general,gmane.comp.security.web-applications
Message-ID <1293032971.3491.10.camel@athlon>
On Tue, 2010-12-21 at 13:44 +0100, Leonard den Ottolander wrote:
> The patch shown in
> http://core.trac.wordpress.org/changeset/16625
> 
> prompted me to try a
> 
> $ grep -r "\=\ \%s\"" *
> 
> in the web root of a WordPress installation. The matches are a bunch of
> possible SQL injections. Haven't checked the actual code paths,

This turned out to a wild goose chase: For all matches the substituted
strings are being quoted via wpdb->prepare().

Regard,
Leonard.

-- 
mount -t life -o ro /dev/dna /genetic/research
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.