<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>JaypeeOnline &#187; xss vulnerability</title> <atom:link href="http://jaypeeonline.net/tag/xss-vulnerability/feed/" rel="self" type="application/rss+xml" /><link>http://jaypeeonline.net</link> <description>Technology, Blogging News, WordPress Theme and Plugin Reviews, Tips and Tricks</description> <lastBuildDate>Mon, 21 May 2012 03:17:06 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=</generator> <item><title>WordPress 2.8.6 Security Release</title><link>http://jaypeeonline.net/wordpress/wordpress-2-8-6-security-release/</link> <comments>http://jaypeeonline.net/wordpress/wordpress-2-8-6-security-release/#comments</comments> <pubDate>Fri, 13 Nov 2009 05:50:39 +0000</pubDate> <dc:creator>Jaypee Habaradas</dc:creator> <category><![CDATA[WordPress]]></category> <category><![CDATA[apache]]></category> <category><![CDATA[wordpress 2.8.6]]></category> <category><![CDATA[WordPress security release]]></category> <category><![CDATA[xss vulnerability]]></category><guid
isPermaLink="false">http://jaypeeonline.net/?p=7163</guid> <description><![CDATA[Just as I finished publishing my previous post, I saw the notification that WordPress 2.8.6 security release is now available for download. Here&#8217;s what the official WordPress blog has to say about this new release: 2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges. If you [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://maxcdn.jaypeeonline.net/images/wplogo.jpg" alt="WordPress Logo" /></p><p>Just as I finished publishing my previous post, I saw the notification that <a
href="http://wordpress.org/development/2009/11/wordpress-2-8-6-security-release/">WordPress 2.8.6 security release</a> is now available for download. Here&#8217;s what the official WordPress blog has to say about this new release:</p><blockquote><p>2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges.  If you have untrusted authors on your blog, upgrading to 2.8.6 is recommended.</p><p>The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch.  The second problem, discovered by Dawid Golunski, is an issue with sanitizing uploaded file names that can be exploited in certain Apache configurations. Thanks to Benjamin and Dawid for finding and reporting these.</p></blockquote><p>If you were having problems accessing this blog earlier, it was because I was upgrading my WordPress install to 2.8.6. Although I trust the other authors on my blog, there&#8217;s always a possibility that some hacker or malicious user can obtain their login details and use that to compromise my blog. I just want to be sure, play safe and prevent any problems or headaches. As I always say, &#8220;better safe than sorry&#8221;. If you have other authors on your blog other than yourself, I strongly encourage you to upgrade to WordPress 2.8.6 now.</p><p><a
href="http://wordpress.org/download/">Get WordPress 2.8.6</a>.</p><div
id="crp_related"><ul><li><a
href="http://jaypeeonline.net/wordpress/wordpress-2-8-4-security-release/" rel="bookmark" class="crp_title">WordPress 2.8.4 Security Release</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-206/" rel="bookmark" class="crp_title">WordPress 2.0.6</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-3-0-2-security-release/" rel="bookmark" class="crp_title">WordPress 3.0.2 Security Release</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-233/" rel="bookmark" class="crp_title">WordPress 2.3.3</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-265/" rel="bookmark" class="crp_title">WordPress 2.6.5</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-2-8-3-security-release/" rel="bookmark" class="crp_title">WordPress 2.8.3 Security Release</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-3-1-3-security-update-wordpress-3-2-beta-2-released/" rel="bookmark" class="crp_title">WordPress 3.1.3 Security Update &#038; WordPress 3.2 Beta 2 Released</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-2-9-2/" rel="bookmark" class="crp_title">WordPress 2.9.2</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-223-security-release/" rel="bookmark" class="crp_title">WordPress 2.2.3 Security Release</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-3-1-2-security-update/" rel="bookmark" class="crp_title">WordPress 3.1.2 Security Update</a></li></ul></div>]]></content:encoded> <wfw:commentRss>http://jaypeeonline.net/wordpress/wordpress-2-8-6-security-release/feed/</wfw:commentRss> <slash:comments>6</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced) (User agent is rejected)
Database Caching 3/8 queries in 0.061 seconds using disk
Object Caching 533/538 objects using disk
Content Delivery Network via maxcdn.jaypeeonline.net

Served from: jaypeeonline.net @ 2012-05-27 15:55:00 -->
