XML-RPC vulnerability found

Posted in Computers & Internet  
E-Mail This Post/Page   

A recently discovered vulnerability in the open source PHP component XML-RPC is leaving many systems vulnerable to attack. Now a virus called Lupper exploits the vulnerability and loads itself on to unpatched systems.

For a list of vulnerable applications, visit SecurityFocus.com. One caveat to the SecurityFocus.com list, Wordpress is reportedly safe from this exploit since version 1.5. According to Wordpress authors the library that version 1.5 upwards uses is called IXR and is different than XML-RPC. Older versions of Wordpress are vulnerable, however.

Digital camera washes ashore with tsunami pictures
11% of identity fraud is online
Syntax highlighting code in WordPress blogs
User-Agent while developing sites
Google Bombing - or how Bush is a miserable failure

Leave a Comment