[wp-trac] [WordPress Trac] #17969: Code Execution vulnerability in WordPress

WordPress Trac wp-trac at lists.automattic.com
Sun Jul 3 15:22:21 UTC 2011


#17969: Code Execution vulnerability in WordPress
--------------------------+----------------------
 Reporter:  macbroadcast  |       Owner:
     Type:  defect (bug)  |      Status:  closed
 Priority:  normal        |   Milestone:
Component:  General       |     Version:  3.2
 Severity:  normal        |  Resolution:  invalid
 Keywords:  needs-patch   |
--------------------------+----------------------

Comment (by nacin):

 You emailed us 2.5 hours ago on a Sunday morning.

 You also emailed a mailing list *before* you emailed
 security at wordpress.org, and then didn't wait for a reply before posting
 here.

 I don't think you being hacked has anything to do with an ongoing attack
 vector. You're welcome to email access logs to security at wordpress.org to
 back up your claim.

 In the meantime, I want to emphasize yet another reason why we encourage
 responsible disclosure versus full disclosure -- the reporter isn't always
 right.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/17969#comment:5>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list