by sathish.k » Thu Nov 03, 2011 1:48 am
A vulnerability in an obscure WordPress add-on script that was discovered back in August is currently being used to compromise over 1.2 million websites and could be easily used to siphon data out of databases hosted on servers also hosting the compromised websites, security experts warned today. Different than the many mass compromises of late that have been accomplished via SQL injection, this attack takes advantage of a local file inclusion (LFI) vulnerability that allows attackers to insert PHP shells onto web servers that can be used as the jumping off point for other attacks, including database hacks.
Thanks & Regards,
Sathish