PDA

View Full Version : xmlrpc.php


ozgreg
12-12-2005, 12:27 AM
Everyone should be aware of this anyway, but back in July 2005 a security flaw was found in this RPC-XML module which effected a wide ranging series of applications (Wordpress, Drupal, Nuke etc) .. (basically any application utilising xmlrpc.php could have been at risk with a remote SQL injection.)

Over the last few weeks, I have noticed an increase in the amount of traffic probing for xmlrpc.php file in a number of common directory structures and want to warn everyone to make sure your applications are fully patched against this exploit.