WordPress 2.7.1 Username Information Disclosure Vulnerability
13 Apr. 2012
Summary
WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source.
Credit:
The information has been provided by Jose Orlicki and Fernando Arnaboldi.
The original article can be found at: http://www.osvdb.org/55716
WordPress could allow a remote attacker to obtain sensitive information, caused by the placement of an author's username in an HTML comment. A remote attacker could exploit this vulnerability to read and obtain sensitive information
Vendor Status:
Wordpress has issued an update for this Vulnerability
Disclosure Timeline:
Vendor Informed Date 2009-06-04
Vendor Ack Date 2009-06-10
Vendor Solution Date 2009-07-07
Disclosure Date 2009-07-08
Exploit Publish Date 2009-07-08