Benjamin Flesch = definitely rocks.”> How to play with an Wordpress Admin ~ mybeNi websecurity, web security and hack stuff.

web securitymybeNi websecurity

How to play with an Wordpress Admin

February 17th, 2007

Just found some XSS which could affect every Wordpress.com Blog Admin out there, the link’s on the bottom of this Post.

Some hours later I stumbled over another interesting flaw, a Redirection Script inside Wordpress, just add /wp-login.php?action=logout&redirect_to=http://mybeni.tk to the blog root and you can send people anywhere you want (I’m sad this doesnt work with the “data:text/html” stuff)

For the folks with the ability to decompile Flash applets, please have a look at this Link: Seems like someone could run his specially craftet PHP script on the wordpress.com server, would be nice if you contact me.

Some XSS on every wordpress.com blog out there, works only on the admin panel of the blog (that means only on the admin): Wordpress.com XSS




Leave a Reply


Google Traffic (7 days)

250
200
150
100
50
134
217
217
196
190
190
198
38.107.191.100