WordPress 1.5.X flaw?

Discussion in 'WordPress' started by TommyD, Mar 6, 2006.

  1. #1
    Was there a flaw that allowed people to inject sql commands?

    I am looking a possible server issue, but I'm wondering if the blog had something to do with it. An account had wordpress, and the database disappeared. Covering all bases.

    thx,

    tom


    Follow-up: Possible db was still there, user was gone. Any info would help. thx. tom
     
    TommyD, Mar 6, 2006 IP
  2. sarahk

    sarahk iTamer Staff

    Messages:
    28,826
    Likes Received:
    4,541
    Best Answers:
    123
    Trophy Points:
    665
    #2
    Sounds nasty. Have you checked the wordpress forums?
     
    sarahk, Mar 7, 2006 IP
  3. TommyD

    TommyD Peon

    Messages:
    1,397
    Likes Received:
    76
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Yes.

    There is mentioning of SQL insertion, but even it that is true, the potential for doing anything is there. So to limit it down to what was reported is too easy, and I didn't want fall into the catch-all support answers: "Customer error, let's upgrade and restore" or "Virus, let's upgrade and restore" or "Security flaw, let's upgrade and restore".

    After years of myself hearing this, they seem a little watered down. ;)

    Thx,

    tom
     
    TommyD, Mar 7, 2006 IP
  4. fsmedia

    fsmedia Prominent Member

    Messages:
    5,163
    Likes Received:
    262
    Best Answers:
    0
    Trophy Points:
    390
    #4
    That's why you should upgrade to 2.x ;)

    But actually, I've been talking with the developers online and we're considering releasing a 1.5.3 version to fix some of the flaws and make people happy with staying on 1.5.x. I myself have a couple blogs still on 1.5.x, but mostly they are 2.x now. I suggest upgrading to 2.x though.
     
    fsmedia, Mar 7, 2006 IP
  5. TommyD

    TommyD Peon

    Messages:
    1,397
    Likes Received:
    76
    Best Answers:
    0
    Trophy Points:
    0
    #5
    When 2.0 came out, some people didn't like that move, so they spent much time posting 'negative' things about it. So, it has tainted some people's view of it. So, I can see why some people don't want to do it just yet.

    But in this case the site was restored, from a backup, and the latest WordPress release is being used.

    Just that if there was a 'human' involved with the crash, I want to try and isolated the potential of that happening again. ;)

    thx,

    tom
     
    TommyD, Mar 7, 2006 IP
  6. Cheyne

    Cheyne Peon

    Messages:
    351
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #6
    I was one of the 2.x haters, but keep using it and you will learn to love it.
     
    Cheyne, Mar 7, 2006 IP