Serious Security Flaw in Wordpress allows Site Visitors to Take Over your Blog

Fri, Jun 26, 2009

Security, WordPress

Advertisements

Jeff Starr discovered serious vulnerability in Wordpress when his server crashed and his blog completely lost connection with MySQL databases. Whenever Wordpress encounters database errors it shows default error page which shows you the details of error. But this is not the case for all database errors, if your Wordpress blog completely lose database connection or your database is entirely missing, then WordPress assumes that it has not yet been installed and loads the installation page to your blog/site visitors.

WordPress-installation-page

And eventually may lead anyone to take over your entire blog.

success-Wordpress-installed

For more info on this issue and fixes refer to Jeff Starr’s post important security fix for Wordpress.

(images via Perishable Press)

Blog Widget by LinkWithin

Related Posts

Bookmark and Share

Bookmark with Delicious Digg it Stumble it Share on Facebook Share in Lindedin Mixx it Tweet this post Subscrine to RSS feed Share/Save/Bookmark


5 Responses to “Serious Security Flaw in Wordpress allows Site Visitors to Take Over your Blog”

  1. Curious Little Person Says:

    Thks for the info… but how do we protect ourselves from this?

    Cheers
    Sandeep
    .-= Curious Little Person´s last blog ..Make Money Online Series Part 2 – EBooks & Reports =-.

    Reply

    • Hariharakumar Says:

      @Curious Little Person

      I have placed the link of the source article where you will find some fixes to this issue, but anyways the simplest fix is to delete the wp-admin/install.php file entirely. It is not needed after installation.

      Reply

  2. Anish K.S Says:

    Thanks for sharing the info.

    Reply

  3. Rahul Says:

    so, whats the solution?

    Reply

  4. Pavan Somu Says:

    hahah fellows can easily stole our accounts

    Reply


Leave a Reply