| lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
|
Open Source and information security mailing list archives
| ||
|
Message-ID: <51D546D2.90608@gmail.com> Date: Thu, 04 Jul 2013 11:56:34 +0200 From: Sven Kieske <svenkieske@...il.com> To: vuln@...unia.com, security@...dpress.org, full-disclosure@...ts.grok.org.uk Subject: WordPress User Account Information Leak / Secunia Advisory SA23621 Hi, the mentioned User account Enumeration Weakness stated in Advisory https://secunia.com/advisories/23621/ still exists in the actual version 3.5.2 . The corresponding trac entry for wordpress is closed as "wontfix": https://core.trac.wordpress.org/ticket/1129 Why? Maybe, because the trac bug mentions just version 1.5 as affected? I can easily reproduce this in version 3.5.2 . Please fix this, this bug is 8 years old! Kind Regards Sven Kieske _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists