<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress Cross Site Scripting Vulnerability in templates.php Uncovered</title>
	<atom:link href="http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/</link>
	<description>The leading source of news covering social media and the blogosphere.</description>
	<lastBuildDate>Mon, 13 Feb 2012 09:18:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: How to Handle Security Flaws &#124; Technosailor.com</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-688016</link>
		<dc:creator>How to Handle Security Flaws &#124; Technosailor.com</dc:creator>
		<pubDate>Sat, 29 Nov 2008 20:49:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-688016</guid>
		<description>[...] 5, 2007 &#183; 12 comments   Yesterday, over at Blog Herald, the new management demonstrated the entirely wrong way of handling security flaws. (The flaw I detailed [...]</description>
		<content:encoded><![CDATA[<p>[...] 5, 2007 &middot; 12 comments   Yesterday, over at Blog Herald, the new management demonstrated the entirely wrong way of handling security flaws. (The flaw I detailed [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy Merrett</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-145327</link>
		<dc:creator>Andy Merrett</dc:creator>
		<pubDate>Thu, 11 Jan 2007 00:38:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-145327</guid>
		<description>If we&#039;re talking about estimations lowering and being cemented then I&#039;m finding one right now. There&#039;s a certain tone coming from some that takes an otherwise useful message and turns it into &quot;Listen to me. I&#039;m a coder. I&#039;m wonderful. I&#039;m right&quot;. Maybe that&#039;s what some networks do to people, but it&#039;s a shame to see how the person I thought I was getting to know last year (before they switched networks) has gone all corporate and UTOA.

Still, it doesn&#039;t matter much as I guess they won&#039;t be reading BH for much longer.</description>
		<content:encoded><![CDATA[<p>If we&#8217;re talking about estimations lowering and being cemented then I&#8217;m finding one right now. There&#8217;s a certain tone coming from some that takes an otherwise useful message and turns it into &#8220;Listen to me. I&#8217;m a coder. I&#8217;m wonderful. I&#8217;m right&#8221;. Maybe that&#8217;s what some networks do to people, but it&#8217;s a shame to see how the person I thought I was getting to know last year (before they switched networks) has gone all corporate and UTOA.</p>
<p>Still, it doesn&#8217;t matter much as I guess they won&#8217;t be reading BH for much longer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WeRoam saves the day: Updating WordPress to latest release &#124; PHP Magazine</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-144013</link>
		<dc:creator>WeRoam saves the day: Updating WordPress to latest release &#124; PHP Magazine</dc:creator>
		<pubDate>Mon, 08 Jan 2007 05:28:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-144013</guid>
		<description>[...] The intermittent connection has made me dependent these past few days on the PLDT WeRoam account temporarily assigned to my wife. WeRoam isnâ€™t as fast as Globelines BQ (before the quake) but with it, I manage to check my mails and browse â€œmust-visitâ€ sites such as del.icio.us and Lifehacker. I seldom visit, let alone log into, my blog these days because of the awful connection speeds. Luckily, I managed to open my Google Reader an hour back and read JAngeloâ€™s post about a vulnerability in WordPress, the open source script I use in this site. I promptly logged into my blog and found that version 2.0.6 has been released. [...]</description>
		<content:encoded><![CDATA[<p>[...] The intermittent connection has made me dependent these past few days on the PLDT WeRoam account temporarily assigned to my wife. WeRoam isnâ€™t as fast as Globelines BQ (before the quake) but with it, I manage to check my mails and browse â€œmust-visitâ€ sites such as del.icio.us and Lifehacker. I seldom visit, let alone log into, my blog these days because of the awful connection speeds. Luckily, I managed to open my Google Reader an hour back and read JAngeloâ€™s post about a vulnerability in WordPress, the open source script I use in this site. I promptly logged into my blog and found that version 2.0.6 has been released. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Recommended Update: WordPress 2.0.6 at The Blog Herald</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-143774</link>
		<dc:creator>Recommended Update: WordPress 2.0.6 at The Blog Herald</dc:creator>
		<pubDate>Sun, 07 Jan 2007 20:33:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-143774</guid>
		<description>[...] Blog Software   Jan 7 at 6:31 pm by Markku Seguerra -In light of the recently reported cross&#8211;site scripting vulnerabilities in WordPress, version 2.0.6 has been released to address the said issues in the templates.php file as detailed in these entries from Operation N and Security Focus. (As cited in our related coverage.) [...]</description>
		<content:encoded><![CDATA[<p>[...] Blog Software   Jan 7 at 6:31 pm by Markku Seguerra -In light of the recently reported cross&#8211;site scripting vulnerabilities in WordPress, version 2.0.6 has been released to address the said issues in the templates.php file as detailed in these entries from Operation N and Security Focus. (As cited in our related coverage.) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-143697</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Sun, 07 Jan 2007 18:26:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-143697</guid>
		<description>Okay. I stand corrected. But still, maybe we can do without the nasty vibe a wee bit.</description>
		<content:encoded><![CDATA[<p>Okay. I stand corrected. But still, maybe we can do without the nasty vibe a wee bit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron Brazell</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-143551</link>
		<dc:creator>Aaron Brazell</dc:creator>
		<pubDate>Sun, 07 Jan 2007 13:20:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-143551</guid>
		<description>Mark: I said nothing about the story until &lt;em&gt;after&lt;/em&gt; WordPress 2.0.6 was officially released. That is, not a beta version, but the offiicial version. I didn&#039;t even say anything on Blog Herald. Granted, I didn&#039;t see it here until after 2.0.6 was released or I probably would have said something privately.

David: 

1. Blog Herald is not the sole irresponsible party here. But they are the one with the biggest bullhorn. The original posters that were quoted also bear responsiblity. And what about the people who don&#039;t read BH that use WordPress. Are they responsible finding out about the  &quot;patch&quot; provided here and implementing it for themselves?

2. Where is this debate? It seems the only debate is between black hat and white hat hackers. Do you subscribe to Bugtraq? Do you see the thousands of bug reports that are reported every month?

As for WordPress&#039; fix, yeah - they rushed 2.0.6 out the door because of stuff like this being public and in the process &lt;a href=&quot;http://neosmart.net/blog/archives/317&quot; rel=&quot;nofollow&quot;&gt;broke something else&lt;/a&gt; because it was a rush job. Now they have to look at 2.0.7 to fix that. Come on, don&#039;t give me what is responsible and what is not.

3. See #2.

4. No one but now hackers know and the rest of the world knows.</description>
		<content:encoded><![CDATA[<p>Mark: I said nothing about the story until <em>after</em> WordPress 2.0.6 was officially released. That is, not a beta version, but the offiicial version. I didn&#8217;t even say anything on Blog Herald. Granted, I didn&#8217;t see it here until after 2.0.6 was released or I probably would have said something privately.</p>
<p>David: </p>
<p>1. Blog Herald is not the sole irresponsible party here. But they are the one with the biggest bullhorn. The original posters that were quoted also bear responsiblity. And what about the people who don&#8217;t read BH that use WordPress. Are they responsible finding out about the  &#8220;patch&#8221; provided here and implementing it for themselves?</p>
<p>2. Where is this debate? It seems the only debate is between black hat and white hat hackers. Do you subscribe to Bugtraq? Do you see the thousands of bug reports that are reported every month?</p>
<p>As for WordPress&#8217; fix, yeah &#8211; they rushed 2.0.6 out the door because of stuff like this being public and in the process <a href="http://neosmart.net/blog/archives/317" rel="nofollow">broke something else</a> because it was a rush job. Now they have to look at 2.0.7 to fix that. Come on, don&#8217;t give me what is responsible and what is not.</p>
<p>3. See #2.</p>
<p>4. No one but now hackers know and the rest of the world knows.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Kierznowski</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-143480</link>
		<dc:creator>David Kierznowski</dc:creator>
		<pubDate>Sun, 07 Jan 2007 08:51:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-143480</guid>
		<description>Let me put the record straight:

1. A patch was provided with the original advisory. Therefore, not only was a problem advertised but a solution provided. So who is being irresponsible? The one not spreading the word or the one pointing out the problem and offering a solution. 

2. There is much debate (still) over what is responsible and what is irresponsible with how one releases security holes. In this case a fix was provided with the problem, not to mention WordPress had an overnight patch. 

3. If it is irresponsible for the security community to publish holes, is it not also irresponsible for the software vendor who is releasing a package to the public that has not been sufficiently tested?

4. Who says attackers didn&#039;t already know about the vulnerability? 

Nuff said.</description>
		<content:encoded><![CDATA[<p>Let me put the record straight:</p>
<p>1. A patch was provided with the original advisory. Therefore, not only was a problem advertised but a solution provided. So who is being irresponsible? The one not spreading the word or the one pointing out the problem and offering a solution. </p>
<p>2. There is much debate (still) over what is responsible and what is irresponsible with how one releases security holes. In this case a fix was provided with the problem, not to mention WordPress had an overnight patch. </p>
<p>3. If it is irresponsible for the security community to publish holes, is it not also irresponsible for the software vendor who is releasing a package to the public that has not been sufficiently tested?</p>
<p>4. Who says attackers didn&#8217;t already know about the vulnerability? </p>
<p>Nuff said.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-143474</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Sun, 07 Jan 2007 04:44:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-143474</guid>
		<description>Jeremy- I think that this is understood now and the way you put it here is fine. One lives and learns by one&#039;s mistakes. 

What I don&#039;t get, however, is the way that such feedback is delivered by Aaron Brazell- who is essentially enflaming a story that he himself claims should not be for public consumption, both here and on his own blog. 

Wouldn&#039;t the best way for him to have handled things, given the correct protocol, been to have privately contacted BH editorial staff and asked that the post be taken down? I am sure that he would have received a positive response. 

In the end of the day, I would hope that we&#039;re all pretty much on the same side.</description>
		<content:encoded><![CDATA[<p>Jeremy- I think that this is understood now and the way you put it here is fine. One lives and learns by one&#8217;s mistakes. </p>
<p>What I don&#8217;t get, however, is the way that such feedback is delivered by Aaron Brazell- who is essentially enflaming a story that he himself claims should not be for public consumption, both here and on his own blog. </p>
<p>Wouldn&#8217;t the best way for him to have handled things, given the correct protocol, been to have privately contacted BH editorial staff and asked that the post be taken down? I am sure that he would have received a positive response. </p>
<p>In the end of the day, I would hope that we&#8217;re all pretty much on the same side.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeremy Wright</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-143414</link>
		<dc:creator>Jeremy Wright</dc:creator>
		<pubDate>Sat, 06 Jan 2007 23:19:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-143414</guid>
		<description>For the record, it&#039;s considered irresponsible in security circles to publish or publicize bugs where the software&#039;s creators are currently working actively on a patch (and when the patch is only days away).

Sure, the Blog Herald didn&#039;t publish the details initially, but they still broadened interest in it needlessly. It&#039;s not a public service if there isn&#039;t anything appropriate the public can do to protect themselves.</description>
		<content:encoded><![CDATA[<p>For the record, it&#8217;s considered irresponsible in security circles to publish or publicize bugs where the software&#8217;s creators are currently working actively on a patch (and when the patch is only days away).</p>
<p>Sure, the Blog Herald didn&#8217;t publish the details initially, but they still broadened interest in it needlessly. It&#8217;s not a public service if there isn&#8217;t anything appropriate the public can do to protect themselves.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Big Roy</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-143301</link>
		<dc:creator>Big Roy</dc:creator>
		<pubDate>Sat, 06 Jan 2007 16:07:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-143301</guid>
		<description>As an independent observer. I think this comment thread reflects more on Mr. Brazell than it does Mr. Racoma&#039;s post.</description>
		<content:encoded><![CDATA[<p>As an independent observer. I think this comment thread reflects more on Mr. Brazell than it does Mr. Racoma&#8217;s post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tony</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-143296</link>
		<dc:creator>Tony</dc:creator>
		<pubDate>Sat, 06 Jan 2007 15:43:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-143296</guid>
		<description>I guess we&#039;ll have to work doubly hard, then. ;)

t</description>
		<content:encoded><![CDATA[<p>I guess we&#8217;ll have to work doubly hard, then. ;)</p>
<p>t</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron Brazell</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-143259</link>
		<dc:creator>Aaron Brazell</dc:creator>
		<pubDate>Sat, 06 Jan 2007 14:32:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-143259</guid>
		<description>Tony: My opinion wasn&#039;t changed. It was merely cemented.</description>
		<content:encoded><![CDATA[<p>Tony: My opinion wasn&#8217;t changed. It was merely cemented.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tony</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-143113</link>
		<dc:creator>Tony</dc:creator>
		<pubDate>Sat, 06 Jan 2007 05:46:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-143113</guid>
		<description>I think what Aaron was commenting on was the usual way of dealing with vulnerabilities and exploits to minimize the chance of publicizing the vulnerabilities to hackers.

However, without speaking too much for Angelo, I think I&#039;ll agree with Abe here -- the intention was never to do the wrong thing in pursuit of the scoop.

If this security publishing faux pas has changed your opinion about the BlogHerald, I&#039;m sorry for that -- but I think our new columnists are doing their damndest to try and make it better.

And hopefully in the New Year we can make you a believer too. ;)

Cheers,
Tony.</description>
		<content:encoded><![CDATA[<p>I think what Aaron was commenting on was the usual way of dealing with vulnerabilities and exploits to minimize the chance of publicizing the vulnerabilities to hackers.</p>
<p>However, without speaking too much for Angelo, I think I&#8217;ll agree with Abe here &#8212; the intention was never to do the wrong thing in pursuit of the scoop.</p>
<p>If this security publishing faux pas has changed your opinion about the BlogHerald, I&#8217;m sorry for that &#8212; but I think our new columnists are doing their damndest to try and make it better.</p>
<p>And hopefully in the New Year we can make you a believer too. ;)</p>
<p>Cheers,<br />
Tony.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wordpress 2.1&#8242;e az kala &#124; Blog ve Wolkanca.Com - Evden iÅŸe iÅŸten eve Blog!</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-143108</link>
		<dc:creator>Wordpress 2.1&#8242;e az kala &#124; Blog ve Wolkanca.Com - Evden iÅŸe iÅŸten eve Blog!</dc:creator>
		<pubDate>Sat, 06 Jan 2007 04:55:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-143108</guid>
		<description>[...] Wordpress 2.1&#8242;e az kala   wolkanca Kategori: Blog   blog, Guvenlik, Guvenlik aciklari, Surum yukseltme, wordpress  Wordpress 2.06 sÃ¼rÃ¼mÃ¼, geliÅŸtiricilerinin blogunda yazÄ±ldÄ±ÄŸÄ±na gÃ¶re 2.0 serisinin sonu, bundan sonra Ã§Ä±karÄ±lacak sÃ¼rÃ¼mler 2.1 iÃ§in Ã¶n hazÄ±rlÄ±k olacakmÄ±ÅŸ. 2.05 sÃ¼rÃ¼mÃ¼nde acemide okuduÄŸuma gÃ¶re XSS aÃ§Ä±ÄŸÄ± varmÄ±ÅŸ, bende bu yÃ¼zden hemen blogu 2.06 ya yÃ¼kseltmeyi dÃ¼ÅŸÃ¼nÃ¼yorum. Worpress mizin sÃ¼rÃ¼mÃ¼nÃ¼ yÃ¼kseltmek iÃ§in her zamanki gibi Wordpress TÃ¼rkiye belgelerinden faydalanÄ±yoruz. [...]</description>
		<content:encoded><![CDATA[<p>[...] WordPress 2.1&#8242;e az kala   wolkanca Kategori: Blog   blog, Guvenlik, Guvenlik aciklari, Surum yukseltme, wordpress  WordPress 2.06 sÃ¼rÃ¼mÃ¼, geliÅŸtiricilerinin blogunda yazÄ±ldÄ±ÄŸÄ±na gÃ¶re 2.0 serisinin sonu, bundan sonra Ã§Ä±karÄ±lacak sÃ¼rÃ¼mler 2.1 iÃ§in Ã¶n hazÄ±rlÄ±k olacakmÄ±ÅŸ. 2.05 sÃ¼rÃ¼mÃ¼nde acemide okuduÄŸuma gÃ¶re XSS aÃ§Ä±ÄŸÄ± varmÄ±ÅŸ, bende bu yÃ¼zden hemen blogu 2.06 ya yÃ¼kseltmeyi dÃ¼ÅŸÃ¼nÃ¼yorum. Worpress mizin sÃ¼rÃ¼mÃ¼nÃ¼ yÃ¼kseltmek iÃ§in her zamanki gibi WordPress TÃ¼rkiye belgelerinden faydalanÄ±yoruz. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Abe Olandres</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-143105</link>
		<dc:creator>Abe Olandres</dc:creator>
		<pubDate>Sat, 06 Jan 2007 04:45:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-143105</guid>
		<description>Hello Aaron,

It wasn&#039;t as if we were the ones who first discovered the vulnerability prior to v2.0.6, so it wasn&#039;t a &quot;scoop&quot; for us. If you read the post again, you will notice several links to the original sites which cited the problem.

Our intention is to inform and warn people of such vulnerabilities and help them find ways to fix it. Our motive was clear. If you didn&#039;t see the good intention, some other readers &amp; WP users might. While you look at it as irresponsible, some of us look at it as cautiously responsible. We&#039;ll just have to settle with the fact that we can&#039;t really please everybody with what we deliver to our readers.</description>
		<content:encoded><![CDATA[<p>Hello Aaron,</p>
<p>It wasn&#8217;t as if we were the ones who first discovered the vulnerability prior to v2.0.6, so it wasn&#8217;t a &#8220;scoop&#8221; for us. If you read the post again, you will notice several links to the original sites which cited the problem.</p>
<p>Our intention is to inform and warn people of such vulnerabilities and help them find ways to fix it. Our motive was clear. If you didn&#8217;t see the good intention, some other readers &#038; WP users might. While you look at it as irresponsible, some of us look at it as cautiously responsible. We&#8217;ll just have to settle with the fact that we can&#8217;t really please everybody with what we deliver to our readers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: How to Handle Security Flaws &#187; Technology, Blogging and New Media</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-143084</link>
		<dc:creator>How to Handle Security Flaws &#187; Technology, Blogging and New Media</dc:creator>
		<pubDate>Sat, 06 Jan 2007 03:04:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-143084</guid>
		<description>[...] Yesterday, over at Blog Herald, the new management demonstrated the entirely wrong way of handling security flaws. (The flaw I detailed here) [...]</description>
		<content:encoded><![CDATA[<p>[...] Yesterday, over at Blog Herald, the new management demonstrated the entirely wrong way of handling security flaws. (The flaw I detailed here) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron Brazell</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-143079</link>
		<dc:creator>Aaron Brazell</dc:creator>
		<pubDate>Sat, 06 Jan 2007 02:26:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-143079</guid>
		<description>It was released before WP 2.0.6. As it happens, I knew about one of the flaws weeks ago but you didn &#039;t see me post anything on it, did you? The reality is thousands of people use WordPRess and all you can offer them for your hand flailing is a beta version of WordPress 2.0.6.

I think it&#039;s wiser for you to study up on how to handle these issues in the future. It makes you a better citizen. My flailing trust in BH has slipped further due to your demonstrated irresponsibility.</description>
		<content:encoded><![CDATA[<p>It was released before WP 2.0.6. As it happens, I knew about one of the flaws weeks ago but you didn &#8216;t see me post anything on it, did you? The reality is thousands of people use WordPRess and all you can offer them for your hand flailing is a beta version of WordPress 2.0.6.</p>
<p>I think it&#8217;s wiser for you to study up on how to handle these issues in the future. It makes you a better citizen. My flailing trust in BH has slipped further due to your demonstrated irresponsibility.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: J. Angelo Racoma</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-143078</link>
		<dc:creator>J. Angelo Racoma</dc:creator>
		<pubDate>Sat, 06 Jan 2007 02:21:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-143078</guid>
		<description>Aaron,

It wasn&#039;t a scoop--the news would&#039;ve spread even without us posting about it, so I thought it best to post this as a warning. Patching WP to fix bugs would always be a good idea.</description>
		<content:encoded><![CDATA[<p>Aaron,</p>
<p>It wasn&#8217;t a scoop&#8211;the news would&#8217;ve spread even without us posting about it, so I thought it best to post this as a warning. Patching WP to fix bugs would always be a good idea.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WeRoam saves the day: Updating WordPress to latest release &#124; Leon Kilat ::: The Cybercafe Experiments</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-142993</link>
		<dc:creator>WeRoam saves the day: Updating WordPress to latest release &#124; Leon Kilat ::: The Cybercafe Experiments</dc:creator>
		<pubDate>Fri, 05 Jan 2007 21:30:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-142993</guid>
		<description>[...] The intermittent connection has made me dependent these past few days on the PLDT WeRoam account temporarily assigned to my wife. WeRoam isn&#8217;t as fast as Globelines BQ (before the quake) but with it, I manage to check my mails and browse &#8220;must-visit&#8221; sites such as del.icio.us and Lifehacker. I seldom visit, let alone log into, my blog these days because of the awful connection speeds. Luckily, I managed to open my Google Reader an hour back and read JAngeloâ€™s post about a vulnerability in WordPress, the open source script I use in this site. I promptly logged into my blog and found that version 2.0.6 has been released. [...]</description>
		<content:encoded><![CDATA[<p>[...] The intermittent connection has made me dependent these past few days on the PLDT WeRoam account temporarily assigned to my wife. WeRoam isn&#8217;t as fast as Globelines BQ (before the quake) but with it, I manage to check my mails and browse &#8220;must-visit&#8221; sites such as del.icio.us and Lifehacker. I seldom visit, let alone log into, my blog these days because of the awful connection speeds. Luckily, I managed to open my Google Reader an hour back and read JAngeloâ€™s post about a vulnerability in WordPress, the open source script I use in this site. I promptly logged into my blog and found that version 2.0.6 has been released. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron Brazell</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-142985</link>
		<dc:creator>Aaron Brazell</dc:creator>
		<pubDate>Fri, 05 Jan 2007 20:42:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-142985</guid>
		<description>It&#039;s a shame BH couldn&#039;t have acted more responsibly and waited for 2.0.6 to be released before announcing an XSS flaw to the blogging world that predominantly uses WordPress. Sometimes the &quot;scoop&quot; isn&#039;t the wisest choice.</description>
		<content:encoded><![CDATA[<p>It&#8217;s a shame BH couldn&#8217;t have acted more responsibly and waited for 2.0.6 to be released before announcing an XSS flaw to the blogging world that predominantly uses WordPress. Sometimes the &#8220;scoop&#8221; isn&#8217;t the wisest choice.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress&#8217;in 2.0.6 versiyonu yayÄ±nlandÄ± &#187; Acemi Blogcu</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-142971</link>
		<dc:creator>WordPress&#8217;in 2.0.6 versiyonu yayÄ±nlandÄ± &#187; Acemi Blogcu</dc:creator>
		<pubDate>Fri, 05 Jan 2007 19:37:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-142971</guid>
		<description>[...] BugÃ¼n iÅŸ dÃ¶nÃ¼ÅŸÃ¼ evde her zamanki gibi NewsGator&#8217;Ä± kontrol ederken The Blog Herald&#8216;da WordPress 2.0.5&#8242;de keÅŸfedilen bir XSS aÃ§Ä±ÄŸÄ±ndan bahsedildiÄŸine rastladÄ±m. GÃ¼venlik aÃ§Ä±ÄŸÄ± nedeni ile &#8220;Acaba henÃ¼z beta durumundaki WordPress 2.0.6&#8242;ya mÄ± yÃ¼kseltsem?&#8221; diye dÃ¼ÅŸÃ¼nÃ¼rken v2.0.6&#8242;nÄ±n wordpress.org&#8217;da yayÄ±nlandÄ±ÄŸÄ±nÄ± farkettim ve tabii hemen gÃ¼ncelledim. Kendinizi daha rahat hissetmenizi saÄŸlayacak bu olayÄ± size de tavsiye ederim :) [...]</description>
		<content:encoded><![CDATA[<p>[...] BugÃ¼n iÅŸ dÃ¶nÃ¼ÅŸÃ¼ evde her zamanki gibi NewsGator&#8217;Ä± kontrol ederken The Blog Herald&#8216;da WordPress 2.0.5&#8242;de keÅŸfedilen bir XSS aÃ§Ä±ÄŸÄ±ndan bahsedildiÄŸine rastladÄ±m. GÃ¼venlik aÃ§Ä±ÄŸÄ± nedeni ile &#8220;Acaba henÃ¼z beta durumundaki WordPress 2.0.6&#8242;ya mÄ± yÃ¼kseltsem?&#8221; diye dÃ¼ÅŸÃ¼nÃ¼rken v2.0.6&#8242;nÄ±n wordpress.org&#8217;da yayÄ±nlandÄ±ÄŸÄ±nÄ± farkettim ve tabii hemen gÃ¼ncelledim. Kendinizi daha rahat hissetmenizi saÄŸlayacak bu olayÄ± size de tavsiye ederim :) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Cross Site Scripting Vulnerability in templates.php &#124; Content Writing and CopyWriting Blog</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-142600</link>
		<dc:creator>WordPress Cross Site Scripting Vulnerability in templates.php &#124; Content Writing and CopyWriting Blog</dc:creator>
		<pubDate>Thu, 04 Jan 2007 22:41:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-142600</guid>
		<description>[...] A Blog Herald post talks about the&#160;scripting vulnerability in WordPress templates.php file&#160;and how to eliminate it: [...]</description>
		<content:encoded><![CDATA[<p>[...] A Blog Herald post talks about the&nbsp;scripting vulnerability in WordPress templates.php file&nbsp;and how to eliminate it: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: J. Angelo Racoma</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-142576</link>
		<dc:creator>J. Angelo Racoma</dc:creator>
		<pubDate>Thu, 04 Jan 2007 20:28:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-142576</guid>
		<description>David,

We all speak Greek (or Geek?) every once in a while. I have a few friends who remind me of that often. Thanks for warning everyone with that WP vulnerability. I&#039;ve a lot of blogs to fix!

Big Roy,

Thanks for the vote of confidence. We&#039;re hoping people would notice the change.</description>
		<content:encoded><![CDATA[<p>David,</p>
<p>We all speak Greek (or Geek?) every once in a while. I have a few friends who remind me of that often. Thanks for warning everyone with that WP vulnerability. I&#8217;ve a lot of blogs to fix!</p>
<p>Big Roy,</p>
<p>Thanks for the vote of confidence. We&#8217;re hoping people would notice the change.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Big Roy</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-142564</link>
		<dc:creator>Big Roy</dc:creator>
		<pubDate>Thu, 04 Jan 2007 18:21:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-142564</guid>
		<description>I started reading The Blog Herald before I ever started my own blog. As time went on I found I wasn&#039;t really happy with the tone being set.

I have to say the &quot;new&quot; Blog Herald is a big change. The articles are useful, original, and enjoyable to read. It&#039;s obvious you guys aren&#039;t just rehashing a bunch of stuff from other blogs.

This isn&#039;t a dig at Matt in any way. I like him a lot and his writing. He gave me one of the first links to my blog.

Thanks for the heads up on Wordpress.</description>
		<content:encoded><![CDATA[<p>I started reading The Blog Herald before I ever started my own blog. As time went on I found I wasn&#8217;t really happy with the tone being set.</p>
<p>I have to say the &#8220;new&#8221; Blog Herald is a big change. The articles are useful, original, and enjoyable to read. It&#8217;s obvious you guys aren&#8217;t just rehashing a bunch of stuff from other blogs.</p>
<p>This isn&#8217;t a dig at Matt in any way. I like him a lot and his writing. He gave me one of the first links to my blog.</p>
<p>Thanks for the heads up on WordPress.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wednesday Links</title>
		<link>http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/comment-page-1/#comment-142534</link>
		<dc:creator>Wednesday Links</dc:creator>
		<pubDate>Thu, 04 Jan 2007 15:39:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2007/01/04/wordpress-cross-site-scripting-vulnerability-in-templatesphp-uncovered/#comment-142534</guid>
		<description>[...] WordPress Cross Site Scripting Vulnerability Uncovered [...]</description>
		<content:encoded><![CDATA[<p>[...] WordPress Cross Site Scripting Vulnerability Uncovered [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

