What's HTML?
Gender:
Posts: 402
2430 credits Members referred : 2
« Reply #3 on: Aug 01, 2007, 03:33:44 PM »
Nikolas, I don't think they want to make a big fuss about the vulnerabilities, since they don't want people to get ideas about attacking other wordpress sites ...
most of the vulnerabilities are only if the attacker has admin rights...
What do you mean. Is it possible to get admin rights for anyone or do they need to have the admin password to use the vulnerabilities or do you mean that admins with too low security on their passwords are easy targets?
I have about 7 blogs I need to upgrade so I guess I better start today
/Andreas
Global Moderator Community Supporter?
Jedai Sword Master
Gender:
Posts: 6307
38662 credits Members referred : 374
most of the vulnerabilities are only if the attacker has admin rights...
What do you mean. Is it possible to get admin rights for anyone or do they need to have the admin password to use the vulnerabilities or do you mean that admins with too low security on their passwords are easy targets?
I have about 7 blogs I need to upgrade so I guess I better start today
Tim Nash
Global Moderator Community Supporter?
Internet Junkie
Posts: 2173
5036 credits Members referred : 2
Venture Skills - New Media & IT group
« Reply #7 on: Aug 02, 2007, 01:06:31 PM »
not in all cases though however the worm works by getting an admin to click the link and therefore give the admin rights.
Now a malicious worm would say send a trackback to you, you see it in the stats what do you do? So having a strong password in this scenario won't help