+ Reply to Thread
Page 2 of 2 FirstFirst 1 2
Results 11 to 19 of 19

Thread: WordPress 2.8.2 On The Way?

  1. #11
    Jeffro's Avatar
    Jeffro is offline WPTavern Forum Admin
    Join Date
    Jan 2009
    Location
    Ohio
    Posts
    2,107

    Default

    I didn't think of it that way but you're right

  2. #12
    Otto's Avatar
    Otto is offline Trac Master
    Join Date
    Apr 2009
    Location
    Memphis, TN
    Posts
    770

    Default

    Here's the security changes:
    http://core.trac.wordpress.org/chang...=11719%40trunk

    Short version: The comment author email was not properly escaped, so it was/is possible to put code into there which would get displayed on the page. It was not particularly *easy* to do that, mind you, but it was still possible.

    Security risk: Medium. It's an XSS bug, exploiting it is difficult but can be automated. If you allow comments, you're vulnerable. It would difficult to exploit this to gain deeper access to the site, due to the limited field size.

    Most likely attack: Annoyance factor. Somebody could, for example, make a comment that caused the page to redirect when displayed.

  3. #13
    joetek's Avatar
    joetek is offline Hello World
    Join Date
    Feb 2009
    Location
    Toronto, Ontario
    Posts
    58

    Default

    Even if you have had trouble with the autoupgrader, you could download it directly to your webhost and unzip it in place instead of downloading it to your computer, unzipping and then uploading to your webhost. That would likely be a faster option.

    Looks like WPMU has been updated as well http://mu.wordpress.org/download/
    Joe Taiabjee
    work: b5media.com - blog: joetek.ca - twitter: @joetek

  4. #14
    Martin's Avatar
    Martin is offline Here For The Peanuts
    Join Date
    Jun 2009
    Location
    Sydney, Australia
    Posts
    115

    Default

    Manual upgrading is very easy and takes less then 5 minutes when I sometimes do it.

    Delete the following folders and their content: wp-includes, wp-admin

    Delete all loose WordPress files in the root of your install except one file: wp-config.php.

    Move across new files not including folders: wp-includes, wp-admin and file wp-config-sample.php.

    Go to the following link to finalize the upgrade: http://www.mysite.com//wp-admin/upgrade.php

    That's it, use to do it like this all the time....

    PS: Starting to like the auto-upgrade feature. Used it on about 40 sites today...
    Last edited by Martin; 07-20-2009 at 12:40 PM.
    Premium WordPress Hosting - WordPress Hosting, Installations and Services.

  5. #15
    itsananderson's Avatar
    itsananderson is offline Big Tipper
    Join Date
    Jan 2009
    Location
    Terre Haute, IN
    Posts
    354

    Default

    I usually just upload the whole archive and overwrite everything (I've configured FileZilla to overwrite without asking). Saves the trouble of deleting anything.

    Of course that's a moot point since I always use the auto up-grader now :)

  6. #16
    andrea_r's Avatar
    andrea_r is offline WPTavern Forum Moderator
    Join Date
    Jan 2009
    Location
    Eastern Canada
    Posts
    1,279

    Default

    Yep, they're working hard to sync WPMU updates with WP ones as the merge gets closer.

    (I'm kinda excited. Can I squee in here?)

  7. #17
    conorp's Avatar
    conorp is offline Kegger
    Join Date
    Jan 2009
    Location
    Australia
    Posts
    504

    Default

    Well auto upgrade is quite slow as well for some reason. Its not the host at its fine on other internet connections
    The lord of every land, rising for them,
    The Aton of the day, great of majesty.

    Great Hymn of the Aton

  8. #18
    chipbennett's Avatar
    chipbennett is online now WordPress Legend
    Join Date
    Feb 2009
    Location
    St. Louis, MO
    Posts
    1,718

    Default

    Quote Originally Posted by Jeffro View Post
    Annnd 2.8.2 is out the door which fixes a XSS vulnerability

    http://wordpress.org/development/200...rdpress-2-8-2/
    Finally had time to auto-upgrade today. All went smoothly, as is, by now, expected.
    WP TurnKey - Turn-Key WordPress installation and maintenance services
    WordPress user since 2005 | @chip_bennett | chipbennett.net | cbnet Plugins

  9. #19
    MiroslavGlavic is offline Here For The Peanuts
    Join Date
    May 2009
    Location
    Toronto, Canada
    Posts
    129

    Default

    upgrade upgrade upgrade upgrade upgrad.

    Did I mention upgrade?

    Most of these attacks are of very lazy admins. You can't just give up after installation.

    You have to maintain your site, do your backups and so forth.

+ Reply to Thread
Page 2 of 2 FirstFirst 1 2

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts