Bugtraq mailing list archives
Re: Wordpress File Inclusion
From: Expanders <expanders () inorbit com>
Date: Mon, 13 Nov 2006 19:09:19 +0100
------------- wp-include/functions.php line:2166 ------------------ function load_template($file) {global $posts, $post, $wp_did_header, $wp_did_template_redirect, $wp_query,
$wp_rewrite, $wpdb; extract($wp_query->query_vars); require_once($file); } -----------------------------------------------------------------you cannot control a variable directly into a function. so this is not a vulnerability
Cheers Expanders
Current thread:
- Wordpress File Inclusion vannovax (Nov 13)
- Re: Wordpress File Inclusion Expanders (Nov 13)
- <Possible follow-ups>
- Re: Wordpress File Inclusion emc3 (Nov 13)