[wp-testers] Possible SQL injection when mail blogging

Auras jay-c at home.ro
Fri Dec 2 14:40:40 GMT 2005


I don't know if this issue has been fixed in WP 2.0, I didn't find 
anything about this on the bugs page but when I tested mail blogging on 
wp 1.5.2 I used this setence "If this works It's cool" and I got a mysql 
error : Error... near "'s cool', '--date--'...". I didn't find any 
addslashes function in wp-mail.php of wp 2.0.



More information about the wp-testers mailing list