<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>System7 &#187; wordpress</title>
	<atom:link href="http://www.system7.org/tag/wordpress/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.system7.org</link>
	<description>Spread the word, information is free.</description>
	<lastBuildDate>Mon, 16 Jan 2012 13:24:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Recent WordPress vulns and the Open Source Vuln DB</title>
		<link>http://www.system7.org/2011/05/12/recent-wordpress-vulns-and-the-open-source-vuln-db/</link>
		<comments>http://www.system7.org/2011/05/12/recent-wordpress-vulns-and-the-open-source-vuln-db/#comments</comments>
		<pubDate>Thu, 12 May 2011 22:52:43 +0000</pubDate>
		<dc:creator>.</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=774</guid>
		<description><![CDATA[There&#8217;s been too many WordPress vulnerabilities for my liking.  Fortunately they seem to be quick to patch but software updates are always a pain. How long before everyone starts to adopt Chrome&#8217;s auto update feature? Luckily, I&#8217;m a fan of &#8230; <a href="http://www.system7.org/2011/05/12/recent-wordpress-vulns-and-the-open-source-vuln-db/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s been t<a href="http://osvdb.org/search/search?search[vuln_title]=&amp;search[text_type]=titles&amp;search[s_date]=&amp;search[e_date]=&amp;search[refid]=&amp;search[referencetypes]=&amp;search[vendors]=wordpress&amp;search[cvss_score_from]=&amp;search[cvss_score_to]=&amp;search[cvss_av]=*&amp;search[cvss_ac]=*&amp;search[cvss_a]=*&amp;search[cvss_ci]=*&amp;search[cvss_ii]=*&amp;search[cvss_ai]=*&amp;kthx=search" target="_blank">oo many WordPress vulnerabilities</a> for my liking.  Fortunately they seem to be quick to patch but software updates are always a pain. How long before everyone starts to adopt <a href="http://www.google.com/intl/en/landing/chrome/google-chrome-privacy-whitepaper.pdf" target="_blank">Chrome&#8217;s auto update</a> <a href="https://code.google.com/p/omaha/" target="_blank">feature</a>?</p>
<p>Luckily, I&#8217;m a fan of the <a href="http://osvdb.org/" target="_blank">Open Source Vuln Database</a> which makes staying on top of security updates that matter to you easy.  Using the OSVDB is as simple as creating an account and search alerts for any software you&#8217;re interested in.  Here&#8217;s what I recently received regarding WP:</p>
<address>Osama, new or updated vulnerabilities that match your search watch list have been foundSEARCH ID: 14</p>
<p>OSVDB_ID:  72173<br />
URL: <a href="http://osvdb.org/show/osvdb/72173" target="_blank">http://osvdb.org/show/osvdb/72173</a></p>
</address>
<address>Title: WordPress Arbitrary File Upload<br />
Disclosure Date: Apr 26, 2011Description: WordPress fails to properly validate uploaded files, allowing a remote attacker to upload a .phtml file with an appended extension (such as .gif) to execute arbitrary PHP code.</p>
</address>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2011/05/12/recent-wordpress-vulns-and-the-open-source-vuln-db/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Drupal Upgrade Procedure</title>
		<link>http://www.system7.org/2009/05/29/drupal-upgrade-procedure/</link>
		<comments>http://www.system7.org/2009/05/29/drupal-upgrade-procedure/#comments</comments>
		<pubDate>Fri, 29 May 2009 21:07:36 +0000</pubDate>
		<dc:creator>.</dc:creator>
				<category><![CDATA[hardware & software]]></category>
		<category><![CDATA[drupal]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=182</guid>
		<description><![CDATA[Drupal is a content management system &#8212; you can think of it as WordPress on steroids. I would like to say that Drupal is majorly lacking in its upgrade procedure. The Drupal upgrade procedure is stone age. Security advisories seem &#8230; <a href="http://www.system7.org/2009/05/29/drupal-upgrade-procedure/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="content">
<p>Drupal is a content management system &#8212; you can think of it as WordPress on steroids.</p>
<p>I would like to say that Drupal is majorly lacking in its upgrade procedure. The Drupal upgrade procedure is stone age. Security advisories seem frequent (good or bad?) which force the need to upgrade.</p>
<p>Who the hell has a 13 step upgrade procedure anymore? With WordPress the update can be handled with a few button clicks from the admin interface. Drupal requires you to FTP into your site&#8230;.and it doesn&#8217;t end there&#8230;</p>
<p>I think we need to get a discussion started about whether or not frequent security advisories is a positive or negative.  I can think of arguments for both sides.</p></div>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2009/05/29/drupal-upgrade-procedure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

