3 ms·
I browsed 3 pages .90% of them are related to external modules. Whereas about wordpress, well no comment. It is not about which one has more vulnerability it is
by mun2mun 17y ago
I browsed 3 pages .90% of them are related to external modules. Whereas about wordpress, well no comment. It is not about which one has more vulnerability it is about design and how the software enforces security. Take a look at drupal prepare query callback http://api.drupal.org/api/function/_db_query_callback/6 http://api.drupal.org/api/function/_db_query_callback/6 with respect to WP's prepare function in wp-db.php(I have WP version 2.7.1). Drupal's code is double checking users data on the other hand WP just unquotes the %s section. Also look at escape function of the same file. It uses addslashes and commented out mysql_real_escape_string function because it is causing problems!! WTF. Also drupal has a very good guidline on writing secure drupal modules http://drupal.org/writing-secure-code http://drupal.org/writing-secure-code. Show me a equivalent in WP. So your popularity proportional to vulnerability theory is mostly flawed.