"b2 0.6.2 and prior" allow sql injection in ./blog.header.php. $posts isn�t convert to integer, so we can inject a sql in this variable. In MySQL 4.x UNION and subselects can be used to obtain privileges. git-svn-id: http://svn.automattic.com/wordpress/trunk@153 1a063a9b-81f0-0310-95a4-ce76da25c4cd
Description
Languages
PHP
66%
JavaScript
17.2%
CSS
15.6%
SCSS
1%
HTML
0.2%