Snoopy PHP Webclient Security

There is a security advisory out regarding a Snoopy PHP Webclient vulnerability. Since WordPress uses Snoopy internally, we immediately double-checked to be sure that WP isn’t affected. It’s not.

WordPress uses Snoopy internally to fetch RSS feeds for display in the
Dashboard. But by default, all the URLs are hardcoded, and thus not vulnerable to the bug mentioned above. The only way that a WordPress site could be affected is if it had some sort of plugin that allowed users to supply custom feed URLs to the system, and the site had users that the admin could not trust (and who had enough access to provide their own feeds to the plugin).

Stumble It!
Snoopy PHP Webclient Security

Related posts:

  1. WP-Cache fix for Content-Type in feeds
    " If you run a busy WordPress site, or even if your site just has a lot of processor-intensive plugins, then you probably already run..."
  2. WordPress 1.5.2 Security FUD
    " There is some misleading FUD going around about a vulnerability in WordPress 1.5.2. Let’s get this out of the way plainly: There is not..."
  3. WordPress Security Update
    " We were recently notified of a SQL injection bug in the WordPress code. Matt patched the code and updated the archive on the downloads..."
  4. Text Filter Suite Plugin for WordPress
    "Since Talk Like a Pirate Day is only three weeks away, I spent some time this weekend revamping my old Fun Filters hack. The result..."
  5. Creating a secure WordPress install
    " Over on BlogSecurity, there’s a whitepaper on How to create a secure WordPress install. It covers several areas, including MySQL setup, WordPress user configuration,..."
This entry was posted in Security, WordPress and tagged , , , , , . Bookmark the permalink. Post a comment or leave a trackback: Trackback URL.

2 Comments

  1. Ozzie blog.permagnus.com
    Posted October 27, 2005 at 12:11 am | Permalink

    Well thanks for the headsup Doug ;)

  2. Mega ?????? dachnikov.net
    Posted June 15, 2008 at 4:12 am | Permalink

    I’m using Snoopy. It’s good stuff.

One Trackback

  1. [...] geek ramblings » Snoopy PHP Webclient Security There is a security advisory out regarding a Snoopy PHP Webclient vulnerability. Since WordPress uses Snoopy internally, we immediately double-checked to be sure that WP isn’t affected. It’s not. [...]

Post a Comment

Your email is never published nor shared.

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Subscribe without commenting