Advertisement
Guest User

output

a guest
Jul 27th, 2016
145
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.84 KB | None | 0 0
  1. [+] URL: http://brbadvisors.com/
  2. [+] Started: Wed Jul 27 08:38:47 2016
  3.  
  4. [+] robots.txt available under: 'http://brbadvisors.com/robots.txt'
  5. [+] Interesting entry from robots.txt: http://brbadvisors.com/wp-admin/admin-ajax.php
  6. [!] The WordPress 'http://brbadvisors.com/readme.html' file exists exposing a version number
  7. [+] Interesting header: LINK: <http://brbadvisors.com/wp-json/>; rel="https://api.w.org/", <http://wp.me/P7J0yH-ju>; rel=shortlink
  8. [+] Interesting header: SERVER: nginx/1.10.1
  9. [+] This site has 'Must Use Plugins' (http://codex.wordpress.org/Must_Use_Plugins)
  10. [+] XML-RPC Interface available under: http://brbadvisors.com/xmlrpc.php
  11. [!] Upload directory has directory listing enabled: http://brbadvisors.com/wp-content/uploads/
  12. [!] Includes directory has directory listing enabled: http://brbadvisors.com/wp-includes/
  13.  
  14. [+] WordPress version 4.5.3 identified from advanced fingerprinting (Released on 2016-06-21)
  15.  
  16. [+] WordPress theme in use: onepress - v1.2.4
  17.  
  18. [+] Name: onepress - v1.2.4
  19. | Latest version: 1.2.4 (up to date)
  20. | Location: http://brbadvisors.com/wp-content/themes/onepress/
  21. | Readme: http://brbadvisors.com/wp-content/themes/onepress/readme.txt
  22. [!] An error_log file has been found: http://brbadvisors.com/wp-content/themes/onepress/error_log
  23. | Style URL: http://brbadvisors.com/wp-content/themes/onepress/style.css
  24. | Theme Name: OnePress
  25. | Theme URI: https://www.famethemes.com/themes/onepress/
  26. | Description: OnePress is an outstanding creative and flexible WordPress one page theme well suited for busines...
  27. | Author: FameThemes
  28. | Author URI: http://www.famethemes.com
  29.  
  30. [+] Enumerating plugins from passive detection ...
  31. | 2 plugins found:
  32.  
  33. [+] Name: contact-form-7
  34. | Latest version: 4.4.2
  35. | Location: http://brbadvisors.com/wp-content/plugins/contact-form-7/
  36. [!] Directory listing is enabled: http://brbadvisors.com/wp-content/plugins/contact-form-7/
  37.  
  38. [!] We could not determine a version so all vulnerabilities are printed out
  39.  
  40. [!] Title: Contact Form 7 <= 3.7.1 - Security Bypass Vulnerability
  41. Reference: https://wpvulndb.com/vulnerabilities/7020
  42. Reference: http://www.securityfocus.com/bid/66381/
  43. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2265
  44. [i] Fixed in: 3.7.2
  45.  
  46. [!] Title: Contact Form 7 <= 3.5.2 - File Upload Remote Code Execution
  47. Reference: https://wpvulndb.com/vulnerabilities/7022
  48. Reference: http://packetstormsecurity.com/files/124154/
  49. [i] Fixed in: 3.5.3
  50.  
  51. [+] Name: jetpack
  52. | Latest version: 4.1.1
  53. | Location: http://brbadvisors.com/wp-content/plugins/jetpack/
  54. | Changelog: http://brbadvisors.com/wp-content/plugins/jetpack/changelog.txt
  55. [!] Directory listing is enabled: http://brbadvisors.com/wp-content/plugins/jetpack/
  56.  
  57. [!] We could not determine a version so all vulnerabilities are printed out
  58.  
  59. [!] Title: Jetpack <= 2.9.2 - class.jetpack.php XML-RPC Access Control Bypass
  60. Reference: https://wpvulndb.com/vulnerabilities/7203
  61. Reference: http://jetpack.me/2014/04/10/jetpack-security-update/
  62. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0173
  63. Reference: https://secunia.com/advisories/57729/
  64. [i] Fixed in: 2.9.3
  65.  
  66. [!] Title: Jetpack 3.0-3.4.2 - Cross-Site Scripting (XSS)
  67. Reference: https://wpvulndb.com/vulnerabilities/7915
  68. Reference: https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html
  69. Reference: https://jetpack.me/2015/04/20/jetpack-3-4-3-coordinated-security-update/
  70. [i] Fixed in: 3.4.3
  71.  
  72. [!] Title: Jetpack <= 3.5.2 - Unauthenticated DOM Cross-Site Scripting (XSS)
  73. Reference: https://wpvulndb.com/vulnerabilities/7964
  74. Reference: https://blog.sucuri.net/2015/05/jetpack-and-twentyfifteen-vulnerable-to-dom-based-xss-millions-of-wordpress-websites-affected-millions-of-wordpress-websites-affected.html
  75. [i] Fixed in: 3.5.3
  76.  
  77. [!] Title: Jetpack <= 3.7.0 - Stored Cross-Site Scripting (XSS)
  78. Reference: https://wpvulndb.com/vulnerabilities/8201
  79. Reference: https://jetpack.me/2015/09/30/jetpack-3-7-1-and-3-7-2-security-and-maintenance-releases/
  80. Reference: https://blog.sucuri.net/2015/10/security-advisory-stored-xss-in-jetpack.html
  81. [i] Fixed in: 3.7.1
  82.  
  83. [!] Title: Jetpack <= 3.7.0 - Information Disclosure
  84. Reference: https://wpvulndb.com/vulnerabilities/8202
  85. Reference: https://jetpack.me/2015/09/30/jetpack-3-7-1-and-3-7-2-security-and-maintenance-releases/
  86. [i] Fixed in: 3.7.1
  87.  
  88. [!] Title: Jetpack <= 3.9.1 - LaTeX HTML Element XSS
  89. Reference: https://wpvulndb.com/vulnerabilities/8472
  90. Reference: https://jetpack.com/2016/02/25/jetpack-3-9-2-maintenance-and-security-release/
  91. Reference: https://github.com/Automattic/jetpack/commit/dbc33b9105c4dbb0de81544e682a8b6d5ab7e446
  92. [i] Fixed in: 3.9.2
  93.  
  94. [!] Title: Jetpack 2.0-4.0.2 - Shortcode Stored Cross-Site Scripting (XSS)
  95. Reference: https://wpvulndb.com/vulnerabilities/8500
  96. Reference: https://jetpack.com/2016/05/27/jetpack-4-0-3-critical-security-update/
  97. Reference: http://wptavern.com/jetpack-4-0-3-patches-a-critical-xss-vulnerability
  98. Reference: https://blog.sucuri.net/2016/05/security-advisory-stored-xss-jetpack-2.html
  99. [i] Fixed in: 4.0.3
  100.  
  101. [!] Title: Jetpack <= 4.0.3 - Multiple Vulnerabilities
  102. Reference: https://wpvulndb.com/vulnerabilities/8517
  103. Reference: https://jetpack.com/2016/06/20/jetpack-4-0-4-bug-fixes/
  104. [i] Fixed in: 4.0.4
  105.  
  106. [+] Enumerating usernames ...
  107. [+] Identified the following 1 user/s:
  108. +----+-------------------+--------------------------+
  109. | Id | Login | Name |
  110. +----+-------------------+--------------------------+
  111. | 1 | infoheartland-tax | info@heartland.tax – BRB |
  112. +----+-------------------+--------------------------+
  113.  
  114. [+] Finished: Wed Jul 27 08:39:41 2016
  115. [+] Requests Done: 87
  116. [+] Memory used: 94.527 MB
  117. [+] Elapsed time: 00:00:54
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement