-
Website
http://www.matasano.com/log -
Original page
http://www.matasano.com/log/1019/funny/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
Press Controls
3 comments · 2 points
-
ChrisMtso
12 comments · 1 points
-
Eric Monti
11 comments · 1 points
-
StatlerAndWaldorf
12 comments · 3 points
-
Dave G.
7 comments · 1 points
-
-
Popular Threads
Perhaps by now you already know your'e wrong. PHP_SELF is as much vulnerable as REQUEST_URI.
Peace. Lets see what gobless saz :]
I probably should have been more clear in the idea I was expressing but I was too busy snorting a perfectly good bottle of wine out of my nose.
No, it's because pending/draft posts are only displayed in the administration interface (on the "manage posts" page, etc).
The issue here is that WordPress classifies posts along two axes, published-unpublished and public-private. The exploit reveals (unpublished & public) data only; posts marked as "private" stay private, even though an administrator would be able to see them.
BURSA SOHBET
ISTANBUL CHAT
ISLAMI CHAT
IZMIR CHAT
ANKARA ARKADAS
ALMANYA CHAT
TURKEY CHAT
MYNET
SITENE EKLE
VIDEO KLIP IZLE