Telah ditemukan lubang keamanan yang memungkinkan perentas melakukan SQL Injection pada WordPress yang diinstall WP E-commerce 3.8.6. Lubang keamanannnya ada di file wp-shopping-cart.php, wpsc-functions.php, chronopay.php
Saya belum sempat cek dalamnya, tapi sebagai tindakan keamanan saat ini sebaiknya pada plugin WP Firewall 2 saja karena plugin ini cukup ampuh mencegah SQL Injection. Mudah-mudahan bisa segera diperbaiki. Jika update-nya rilis, segera lakukan upgrade ya
17 replies on “WP E-Commerce 3.8.6 SQL Injection Vulnerability”
Kayanya niatan buat shopping pak lutvi bakal terwujud nih.
Eit.. Maksudna shopping cart buatan pak lutvi.
Wah ngeri juga yah, terima kasih informasinya
jadi, bagusnya apa dong buat jual online with wp???
kelebihannya klo pakek plug in ini ap ya?
sial, gw udah kena hack… š
gimana niy ya cara balikinnya..??
oh, serem juga ya
akhirnya ketemu juga lubangnya..bahaya,,
Bahaya juga memasang plugin yang bisa di hack dan melonggarkan keamanan blog wordpress kita
terima kasih infonya
I simply want to tell you that I’m all new to blogs and truly savored this web-site. More than likely Iām likely to bookmark your website . You definitely come with remarkable article content. Thank you for revealing your blog site.
Nevertheless you pity your Facebook . com mate and wish these people to feel that one or more man or woman pretends to therapy what they say
I loved as much as you will receive carried out right here. The sketch is attractive, your authored material stylish. nonetheless, you command get got an shakiness over that you wish be delivering the following. unwell unquestionably come further formerly again as exactly the same nearly a lot often inside case you shield this increase.
When I initially commented I appear to have clicked the -Notify me when new comments are added- checkbox and now whenever a comment is added I recieve four emails with the exact same comment. Is there an easy method you can remove me from that service? Thank you!
This especially helped my examine, Cheers!
This is really interesting, You’re a very skilled blogger. I’ve joined your rss feed and look forward to seeking more of your excellent post. Also, I’ve shared your web site in my social networks!
Hey there would you mind stating which blog platform you’re working with? I’m planning to start my own blog in the near future but I’m having a difficult time selecting between BlogEngine/Wordpress/B2evolution and Drupal. The reason I ask is because your layout seems different then most blogs and I’m looking for something completely unique. P.S Apologies for being off-topic but I had to ask!
Thank you for the good writeup. It in fact was a amusement account it. Look advanced to far added agreeable from you! By the way, how could we communicate?
Good post. I learn something new and challenging on websites I stumbleupon everyday. It’s always interesting to read through articles from other authors and use something from their sites.