XML-RPC vulnerability found

A recently discovered vulnerability in the open source PHP component XML-RPC is leaving many systems vulnerable to attack. Now a virus called Lupper exploits the vulnerability and loads itself on to unpatched systems.

For a list of vulnerable applications, visit SecurityFocus.com. One caveat to the SecurityFocus.com list, WordPress is reportedly safe from this exploit since version 1.5. According to WordPress authors the library that version 1.5 upwards uses is called IXR and is different than XML-RPC. Older versions of WordPress are vulnerable, however.

This entry was posted in Computers & Internet. Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>