<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.1-alpha-2539" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
		>
	<channel>
		<title>WordPress.com Forums &#187; Topic: URL parameters vulnerable to script injection?</title>
		<link>http://en.forums.wordpress.com/topic/url-parameters-vulnerable-to-script-injection</link>
		<description>WordPress.com Forums &#187; Topic: URL parameters vulnerable to script injection?</description>
		<language>en</language>
		<pubDate>Fri, 24 May 2013 11:37:34 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.1-alpha-2539</generator>
				<atom:link href="http://en.forums.wordpress.com/rss/topic/url-parameters-vulnerable-to-script-injection" rel="self" type="application/rss+xml" />

		<item>
			<title>supportbot on "URL parameters vulnerable to script injection?"</title>
			<link>http://en.forums.wordpress.com/topic/url-parameters-vulnerable-to-script-injection#post-1028657</link>
			<pubDate>Wed, 03 Oct 2012 03:02:09 +0000</pubDate>
			<dc:creator>supportbot</dc:creator>
			<guid isPermaLink="false">1028657@http://en.forums.wordpress.com/</guid>
			<description><![CDATA[<p>You did not specify a blog address or reason for posting when you created this topic.</p>
<p>This support forum is for blogs hosted at WordPress.com. If your question is about a self-hosted WordPress blog then you'll find help at the <a href="http://wordpress.org/support/">WordPress.org forums</a>.</p>
<p>If you don't understand the difference between WordPress.com and WordPress.org, you may find <a href="http://support.wordpress.com/com-vs-org/">this information</a> helpful.</p>
<p>If you forgot to include a link to your blog, you can reply and include it below.  It'll help people to answer your question.</p>
<p>This is an automated message.
</p>
]]></description>
					</item>
		<item>
			<title>bethfreeman on "URL parameters vulnerable to script injection?"</title>
			<link>http://en.forums.wordpress.com/topic/url-parameters-vulnerable-to-script-injection#post-1028656</link>
			<pubDate>Wed, 03 Oct 2012 03:02:09 +0000</pubDate>
			<dc:creator>bethfreeman</dc:creator>
			<guid isPermaLink="false">1028656@http://en.forums.wordpress.com/</guid>
			<description><![CDATA[<p>Hi, I paid for a security review of my wordpress blog and one of the items it came back with is a vulnerability to "extended injection" through URL parameters. </p>
<p>For instance, if you append a parameter to the end of a URL, like this:<br />
<a href="http://examplewordpresssite.com/2011/1051/?D=%00qkoikf" rel="nofollow">http://examplewordpresssite.com/2011/1051/?D=%00qkoikf</a></p>
<p>Then the D parameter gets carried into other URLs on the page, like previous and next entries, comment links, and others.</p>
<p>Is the wordpress team aware of this? Is this a major issue I should be concerned about?  </p>
<p>Thanks,</p>
<p>Elisabeth
</p>
]]></description>
					</item>

	</channel>
</rss>
