BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Wordpress <= v2.1.0 Mar 06 2007 08:29AM
vvitkov (at) intergenia (dot) de [email concealed] (vvitkov intergenia de)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

take a look at http://codex.wordpress.org/Roles_and_Capabilities

By design the administrator can post anything ... even js/html

ciri (at) virtuax (dot) be [email concealed] wrote:
> If you're logged in into wordpress as an admin, your comments aren't properly sanitized, thus allo...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus