lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <CA+9yoX2JYy8bAzWLSymMGjR49dmbJ0OyQ+CLa1EEhQ7V8xpfOQ@mail.gmail.com> Date: Fri, 26 Aug 2011 14:08:26 +0200 From: Miroslav Stampar <miroslav.stampar@...il.com> To: full-disclosure@...ts.grok.org.uk Subject: Question about disclosure of WordPress plugin vulnerabilities Hi. Does anybody know what's the general opinion on disclosure of WordPress plugin vulnerabilities in these two sections: 1) unfiltered string parameter values - while magic_quotes are automatically turned on on WordPress >= 3.0 [1] installations 2) admin ones (requires access to the restricted admin area) Kind regards. References: [1] http://kovshenin.com/archives/wordpress-and-magic-quotes/ -- Miroslav Stampar http://about.me/stamparm _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/