Skip to content

Gossamer Web Design

Websites That Work (530) 583-7989

  • home
    • Divi
    • Elementor
    • Open Source
    • WordPress
  • Web Design
    • Advertising
    • Google Apps
  • SEO & Hosting
  • Security
    • Postfix + Amavis + OpenDKIM + SPF
    • Postfix Service Matrix
  • Contact
    • Cart
    • Checkout
    • My account
    • Shop
    • Resume

WordPress 2.8.4,1 Upgrade

August 13, 2009August 13, 2009 adminAdmin, WordPress

Today we received a security notice:

Affected package: wordpress-2.8.2,1
Type of problem: wordpress — remote admin password reset vulnerability.
Description:
WordPress reports:

A specially crafted URL could be requested that would allow an attacker to bypass a security check to verify a user requested a password reset. As a result, the first account without a key in the database (usually the admin account) would have its password reset and a new password would be emailed to the account owner.

References:

  • URL: <http://wordpress.org/development/2009/08/2-8-4-security-release/>
  • URL: <http://www.milw0rm.com/exploits/9410>

Affects:

  • wordpress <2.8.4,1
  • de-wordpress <2.8.4
  • wordpress-mu <2.8.4a

Our installations of WordPress and WordPress-MU have been updated.

In addition, a review of our logs revealed several hack attempts using admin_topic_action_logging.php. Apparently some IBM systems are vulnerable to this exploit. The offending IPs have been banned from our server.

Admin AccountAttackerHackIpsLogsLt 2Milw0rmPassword ResetRemote AdminSecurity CheckSecurity NoticeSecurity ReleaseUrlVulnerability Description

    Gossamer Computer Services


    We don’t upsell retainers — we deliver outcomes. If it doesn’t make you faster or more visible, we don’t ship it.

    • admin

      “All the way” PowerShell hardening script

      $14.95
      Add to cart
    • Sale! admin

      Software Inventory Module

      $29.99 Original price was: $29.99.$19.99Current price is: $19.99.
      Add to cart
    • admin

      Windows 11 Update Control Policy Bundle (Home + Pro) — Auto Download, Notify to Install

      $9.95
      Add to cart

    • Admin
    • Email
    • FAQs
    • google
    • HP
    • Perl
    • PHP
    • Press Releases
    • Resume
    • Revolt
    • Revolt fork
    • Security
    • SEO
    • Specials
    • Stoat
    • TeamSpeak
    • Unix
    • Web Design
    • Windows
    • WordPress
    • Ubuntu 24.04 (Minimal Server) — VM Firewall Hardening for Stoat
    • Stoat (Revolt fork) — Lockdown Playbook
    • Stoat (Revolt fork) — Lockdown & Org Setup
    • TeamSpeak 3 → TeamSpeak 6 Migration on FreeBSD
    • Match “Account Unknown” Profiles to LocalPath/SID via ProfileList

Gossamer Web Design

Tahoe Reno, NV
530 583-7989
  • home
  • Web Design
  • SEO & Hosting
  • Security
  • Contact
Powered by WordPress | Theme: Astrid by aThemes.

AI Web Design by Gossamer

All Rights Reserved © Gossamer Computer Services