Skip to content

Instantly share code, notes, and snippets.

@jershmagersh
Created September 29, 2013 04:20
Show Gist options
  • Save jershmagersh/6749314 to your computer and use it in GitHub Desktop.
Save jershmagersh/6749314 to your computer and use it in GitHub Desktop.
Wordpress spider output
Here's the first few lines found:
Josh:vulnSpider jr$ ruby vulnSpider.rb
Would you like to search for plugins?
y
Getting most popular tags...
Starting with the most popular: widget
Grabbing links...
Plugin: Image Store
URI: http://wordpress.org/plugins/image-store/changelog/
Version: 3.3.0
Log: Security Update
Plugin: Image Store
URI: http://wordpress.org/plugins/image-store/changelog/
Version: 3.2.9
Log: Security Update
Plugin: Feedweb
URI: http://wordpress.org/plugins/feedweb/changelog/
Version: 1.9
Log: Security problem fixed. Redundant code removed.
Plugin: Feedweb
URI: http://wordpress.org/plugins/feedweb/changelog/
Version: 1.7.4
Log: Serious security issue fixed.
Plugin: Feedweb
URI: http://wordpress.org/plugins/feedweb/changelog/
Version: 1.2.8
Log: Security update.
Plugin: Feedweb
URI: http://wordpress.org/plugins/feedweb/changelog/
Version: 1.2.6
Log: Important security update.
Plugin: Easy
URI: http://wordpress.org/plugins/easy/changelog/
Version: 0.8
Log: The security time comes.
All the input fields are now automatically escaped during the widget saving process. All the escapes techniques are defined for each field separately.
If you define your own item (meaning, if you extend the Easy of by your own bricks), doesn't matter if View or Control you can choose from any WordPress built in sanitize, escape function as well as native PHP functions and functions that comes with this plug-in (more in the Documentation).
Plugin: Hit Sniffer Live Blog Analytics
URI: http://wordpress.org/plugins/hit-sniffer-blog-stats/changelog/
Version: 2.5.9
Log: Security Fix: Option to enable hitsniffer dashboard widget for administrators only. ( Thanks to R. Ramos )
Plugin: Hit Sniffer Live Blog Analytics
URI: http://wordpress.org/plugins/hit-sniffer-blog-stats/changelog/
Version: 1.9.6
Log: Security Fix
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment