Benjamin Flesch = definitely rocks.”> runPHP Wordpress Plugin: SQL Injection Vulnerabilitiy ~ mybeNi websecurity, web security and hack stuff.

web securitymybeNi websecurity

runPHP Plugin for Wordpress: SQL Injection Vulnerability

August 8th, 2007

Yesterday, I have discovered an SQL Injection Vulnerability in the runPHP Plugin for Wordpress made by James Van Lommel.

I definitely like the concept of this Plugin; but whilst playing around with my latest Wordpress 2.2.2 Security Update I found a very nasty SQL Injection flaw:

/wp-admin/post.php?action=edit&post=1/*SQLINJECTION*/%20AND%201′=0

Of course I directly contacted James and told him what has happened - and today, he released a patched Version 2.3.0. So users of this Plugin, please update :o)

And Again, Thank you James for this very fast Patch!




2 Responses to “runPHP Plugin for Wordpress: SQL Injection Vulnerability”:

  1. alex Says:

    The author introduced a new XSS bug in his fix:
    wp-admin/post.php?action=edit&post=%3Cscript%3Ealert(/XSS/)%3C/script%3E


  2. SEO Title Tag Wordpress Plugin Vulnerability: Cross-Site Scripting in my own Homepage ~ mybeNi websecurity Says:

    […] couple of weeks ago it was the runPHP Wordpress Plugin which created a SQL Injection Vulnerability and now the story is continued, and I just thought of another nasty […]


Leave a Reply


Google Traffic (7 days)

250
200
150
100
50
134
217
217
196
190
190
195
38.107.191.102