Guest User

Untitled

a guest
Nov 26th, 2019
331
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 15.01 KB | None | 0 0
  1. root@kali:~/Desktop# uname -a
  2. Linux kali 4.17.0-kali1-686 #1 SMP Debian 4.17.8-1kali1 (2018-07-24) i686 GNU/Linux
  3. root@kali:~/Desktop#
  4. root@kali:~/Desktop# wpscan --url http://10.11.1.251/wp
  5. _______________________________________________________________
  6. __ _______ _____
  7. \ \ / / __ \ / ____|
  8. \ \ /\ / /| |__) | (___ ___ __ _ _ __ ®
  9. \ \/ \/ / | ___/ \___ \ / __|/ _` | '_ \
  10. \ /\ / | | ____) | (__| (_| | | | |
  11. \/ \/ |_| |_____/ \___|\__,_|_| |_|
  12.  
  13. WordPress Security Scanner by the WPScan Team
  14. Version 2.9.4
  15. Sponsored by Sucuri - https://sucuri.net
  16. @_WPScan_, @ethicalhack3r, @erwan_lr, @_FireFart_
  17. _______________________________________________________________
  18.  
  19.  
  20. [i] It seems like you have not updated the database for some time
  21. [i] Last database update: 2018-08-21
  22. [?] Do you want to update now? [Y]es [N]o [A]bort update, default: [N] > n
  23. [+] URL: http://10.11.1.251/wp/
  24. [+] Started: Tue Nov 26 09:15:36 2019
  25.  
  26. [+] Interesting header: SERVER: Apache/2.2.11 (Ubuntu) PHP/5.2.6-3ubuntu4.4 with Suhosin-Patch
  27. [+] Interesting header: X-POWERED-BY: PHP/5.2.6-3ubuntu4.4
  28. [+] XML-RPC Interface available under: http://10.11.1.251/wp/xmlrpc.php [HTTP 200]
  29. [+] Found an RSS Feed: http://10.11.1.251/wp/?feed=rss2 [HTTP 200]
  30. [!] Detected 1 user from RSS feed:
  31. +-------+
  32. | Name |
  33. +-------+
  34. | admin |
  35. +-------+
  36. [!] Full Path Disclosure (FPD) in 'http://10.11.1.251/wp/wp-includes/rss-functions.php':
  37. [!] Includes directory has directory listing enabled: http://10.11.1.251/wp/wp-includes/
  38.  
  39. [+] Enumerating WordPress version ...
  40. [!] The WordPress 'http://10.11.1.251/wp/readme.html' file exists exposing a version number
  41.  
  42. [+] WordPress version 2.8.6 (Released on 2009-11-12) identified from advanced fingerprinting, meta generator, readme, links opml
  43. [!] 29 vulnerabilities identified from the version number
  44.  
  45. [!] Title: WordPress 2.5 - 3.3.1 XSS in swfupload
  46. Reference: https://wpvulndb.com/vulnerabilities/5999
  47. Reference: http://seclists.org/fulldisclosure/2012/Nov/51
  48. [i] Fixed in: 3.3.2
  49.  
  50. [!] Title: WordPress 1.5.1 - 3.5 XMLRPC Pingback API Internal/External Port Scanning
  51. Reference: https://wpvulndb.com/vulnerabilities/5988
  52. Reference: https://github.com/FireFart/WordpressPingbackPortScanner
  53. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0235
  54. [i] Fixed in: 3.5.1
  55.  
  56. [!] Title: WordPress 1.5.1 - 3.5 XMLRPC pingback additional issues
  57. Reference: https://wpvulndb.com/vulnerabilities/5989
  58. Reference: http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html
  59.  
  60. [!] Title: WordPress 2.0 - 3.0.1 wp-includes/comment.php Bypass Spam Restrictions
  61. Reference: https://wpvulndb.com/vulnerabilities/6009
  62. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5293
  63. [i] Fixed in: 3.0.2
  64.  
  65. [!] Title: WordPress 2.0 - 3.0.1 Multiple Cross-Site Scripting (XSS) in request_filesystem_credentials()
  66. Reference: https://wpvulndb.com/vulnerabilities/6010
  67. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5294
  68. [i] Fixed in: 3.0.2
  69.  
  70. [!] Title: WordPress 2.0 - 3.0.1 Cross-Site Scripting (XSS) in wp-admin/plugins.php
  71. Reference: https://wpvulndb.com/vulnerabilities/6011
  72. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5295
  73. [i] Fixed in: 3.0.2
  74.  
  75. [!] Title: WordPress 2.0 - 3.0.1 wp-includes/capabilities.php Remote Authenticated Administrator Delete Action Bypass
  76. Reference: https://wpvulndb.com/vulnerabilities/6012
  77. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5296
  78. [i] Fixed in: 3.0.2
  79.  
  80. [!] Title: WordPress 2.0 - 3.0 Remote Authenticated Administrator Add Action Bypass
  81. Reference: https://wpvulndb.com/vulnerabilities/6013
  82. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5297
  83. [i] Fixed in: 3.0
  84.  
  85. [!] Title: WordPress 2.0.3 - 3.9.1 (except 3.7.4 / 3.8.4) CSRF Token Brute Forcing
  86. Reference: https://wpvulndb.com/vulnerabilities/7528
  87. Reference: https://core.trac.wordpress.org/changeset/29384
  88. Reference: https://core.trac.wordpress.org/changeset/29408
  89. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5204
  90. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5205
  91. [i] Fixed in: 3.9.2
  92.  
  93. [!] Title: WordPress <= 4.0 - Long Password Denial of Service (DoS)
  94. Reference: https://wpvulndb.com/vulnerabilities/7681
  95. Reference: http://www.behindthefirewalls.com/2014/11/wordpress-denial-of-service-responsible-disclosure.html
  96. Reference: https://wordpress.org/news/2014/11/wordpress-4-0-1/
  97. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9034
  98. Reference: https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_long_password_dos
  99. Reference: https://www.exploit-db.com/exploits/35413/
  100. Reference: https://www.exploit-db.com/exploits/35414/
  101. [i] Fixed in: 4.0.1
  102.  
  103. [!] Title: WordPress <= 4.0 - Server Side Request Forgery (SSRF)
  104. Reference: https://wpvulndb.com/vulnerabilities/7696
  105. Reference: http://www.securityfocus.com/bid/71234/
  106. Reference: https://core.trac.wordpress.org/changeset/30444
  107. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9038
  108. [i] Fixed in: 4.0.1
  109.  
  110. [!] Title: WordPress <= 4.4.2 - SSRF Bypass using Octal & Hexedecimal IP addresses
  111. Reference: https://wpvulndb.com/vulnerabilities/8473
  112. Reference: https://codex.wordpress.org/Version_4.5
  113. Reference: https://github.com/WordPress/WordPress/commit/af9f0520875eda686fd13a427fd3914d7aded049
  114. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4029
  115. [i] Fixed in: 4.5
  116.  
  117. [!] Title: WordPress 2.6.0-4.5.2 - Unauthorized Category Removal from Post
  118. Reference: https://wpvulndb.com/vulnerabilities/8520
  119. Reference: https://wordpress.org/news/2016/06/wordpress-4-5-3/
  120. Reference: https://github.com/WordPress/WordPress/commit/6d05c7521baa980c4efec411feca5e7fab6f307c
  121. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5837
  122. [i] Fixed in: 4.5.3
  123.  
  124. [!] Title: WordPress 2.5-4.6 - Authenticated Stored Cross-Site Scripting via Image Filename
  125. Reference: https://wpvulndb.com/vulnerabilities/8615
  126. Reference: https://wordpress.org/news/2016/09/wordpress-4-6-1-security-and-maintenance-release/
  127. Reference: https://github.com/WordPress/WordPress/commit/c9e60dab176635d4bfaaf431c0ea891e4726d6e0
  128. Reference: https://sumofpwn.nl/advisory/2016/persistent_cross_site_scripting_vulnerability_in_wordpress_due_to_unsafe_processing_of_file_names.html
  129. Reference: http://seclists.org/fulldisclosure/2016/Sep/6
  130. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7168
  131. [i] Fixed in: 4.6.1
  132.  
  133. [!] Title: WordPress 2.8-4.6 - Path Traversal in Upgrade Package Uploader
  134. Reference: https://wpvulndb.com/vulnerabilities/8616
  135. Reference: https://wordpress.org/news/2016/09/wordpress-4-6-1-security-and-maintenance-release/
  136. Reference: https://github.com/WordPress/WordPress/commit/54720a14d85bc1197ded7cb09bd3ea790caa0b6e
  137. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7169
  138. [i] Fixed in: 4.6.1
  139.  
  140. [!] Title: WordPress <= 4.7 - Post via Email Checks mail.example.com by Default
  141. Reference: https://wpvulndb.com/vulnerabilities/8719
  142. Reference: https://github.com/WordPress/WordPress/commit/061e8788814ac87706d8b95688df276fe3c8596a
  143. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
  144. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5491
  145. [i] Fixed in: 4.7.1
  146.  
  147. [!] Title: WordPress 2.8-4.7 - Accessibility Mode Cross-Site Request Forgery (CSRF)
  148. Reference: https://wpvulndb.com/vulnerabilities/8720
  149. Reference: https://github.com/WordPress/WordPress/commit/03e5c0314aeffe6b27f4b98fef842bf0fb00c733
  150. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
  151. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5492
  152. [i] Fixed in: 4.7.1
  153.  
  154. [!] Title: WordPress 2.8.1-4.7.2 - Control Characters in Redirect URL Validation
  155. Reference: https://wpvulndb.com/vulnerabilities/8766
  156. Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
  157. Reference: https://github.com/WordPress/WordPress/commit/288cd469396cfe7055972b457eb589cea51ce40e
  158. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6815
  159. [i] Fixed in: 4.7.3
  160.  
  161. [!] Title: WordPress 2.3-4.8.3 - Host Header Injection in Password Reset
  162. Reference: https://wpvulndb.com/vulnerabilities/8807
  163. Reference: https://exploitbox.io/vuln/WordPress-Exploit-4-7-Unauth-Password-Reset-0day-CVE-2017-8295.html
  164. Reference: http://blog.dewhurstsecurity.com/2017/05/04/exploitbox-wordpress-security-advisories.html
  165. Reference: https://core.trac.wordpress.org/ticket/25239
  166. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8295
  167.  
  168. [!] Title: WordPress 2.7.0-4.7.4 - Insufficient Redirect Validation
  169. Reference: https://wpvulndb.com/vulnerabilities/8815
  170. Reference: https://github.com/WordPress/WordPress/commit/76d77e927bb4d0f87c7262a50e28d84e01fd2b11
  171. Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
  172. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9066
  173. [i] Fixed in: 4.7.5
  174.  
  175. [!] Title: WordPress 2.5.0-4.7.4 - Post Meta Data Values Improper Handling in XML-RPC
  176. Reference: https://wpvulndb.com/vulnerabilities/8816
  177. Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
  178. Reference: https://github.com/WordPress/WordPress/commit/3d95e3ae816f4d7c638f40d3e936a4be19724381
  179. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9062
  180. [i] Fixed in: 4.7.5
  181.  
  182. [!] Title: WordPress 2.5.0-4.7.4 - Filesystem Credentials Dialog CSRF
  183. Reference: https://wpvulndb.com/vulnerabilities/8818
  184. Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
  185. Reference: https://github.com/WordPress/WordPress/commit/38347d7c580be4cdd8476e4bbc653d5c79ed9b67
  186. Reference: https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_wordpress_connection_information.html
  187. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9064
  188. [i] Fixed in: 4.7.5
  189.  
  190. [!] Title: WordPress 2.3.0-4.8.1 - $wpdb->prepare() potential SQL Injection
  191. Reference: https://wpvulndb.com/vulnerabilities/8905
  192. Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  193. Reference: https://github.com/WordPress/WordPress/commit/70b21279098fc973eae803693c0705a548128e48
  194. Reference: https://github.com/WordPress/WordPress/commit/fc930d3daed1c3acef010d04acc2c5de93cd18ec
  195. [i] Fixed in: 4.8.2
  196.  
  197. [!] Title: WordPress 2.3.0-4.7.4 - Authenticated SQL injection
  198. Reference: https://wpvulndb.com/vulnerabilities/8906
  199. Reference: https://medium.com/websec/wordpress-sqli-bbb2afcc8e94
  200. Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  201. Reference: https://github.com/WordPress/WordPress/commit/70b21279098fc973eae803693c0705a548128e48
  202. Reference: https://wpvulndb.com/vulnerabilities/8905
  203. [i] Fixed in: 4.7.5
  204.  
  205. [!] Title: WordPress <= 4.8.2 - $wpdb->prepare() Weakness
  206. Reference: https://wpvulndb.com/vulnerabilities/8941
  207. Reference: https://wordpress.org/news/2017/10/wordpress-4-8-3-security-release/
  208. Reference: https://github.com/WordPress/WordPress/commit/a2693fd8602e3263b5925b9d799ddd577202167d
  209. Reference: https://twitter.com/ircmaxell/status/923662170092638208
  210. Reference: https://blog.ircmaxell.com/2017/10/disclosure-wordpress-wpdb-sql-injection-technical.html
  211. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16510
  212. [i] Fixed in: 4.8.3
  213.  
  214. [!] Title: WordPress 2.8.6-4.9 - Authenticated JavaScript File Upload
  215. Reference: https://wpvulndb.com/vulnerabilities/8966
  216. Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  217. Reference: https://github.com/WordPress/WordPress/commit/67d03a98c2cae5f41843c897f206adde299b0509
  218. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17092
  219. [i] Fixed in: 4.9.1
  220.  
  221. [!] Title: WordPress 1.5.0-4.9 - RSS and Atom Feed Escaping
  222. Reference: https://wpvulndb.com/vulnerabilities/8967
  223. Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  224. Reference: https://github.com/WordPress/WordPress/commit/f1de7e42df29395c3314bf85bff3d1f4f90541de
  225. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17094
  226. [i] Fixed in: 4.9.1
  227.  
  228. [!] Title: WordPress <= 4.9.4 - Application Denial of Service (DoS) (unpatched)
  229. Reference: https://wpvulndb.com/vulnerabilities/9021
  230. Reference: https://baraktawily.blogspot.fr/2018/02/how-to-dos-29-of-world-wide-websites.html
  231. Reference: https://github.com/quitten/doser.py
  232. Reference: https://thehackernews.com/2018/02/wordpress-dos-exploit.html
  233. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6389
  234.  
  235. [!] Title: WordPress <= 4.9.6 - Authenticated Arbitrary File Deletion
  236. Reference: https://wpvulndb.com/vulnerabilities/9100
  237. Reference: https://blog.ripstech.com/2018/wordpress-file-delete-to-code-execution/
  238. Reference: http://blog.vulnspy.com/2018/06/27/Wordpress-4-9-6-Arbitrary-File-Delection-Vulnerbility-Exploit/
  239. Reference: https://github.com/WordPress/WordPress/commit/c9dce0606b0d7e6f494d4abe7b193ac046a322cd
  240. Reference: https://wordpress.org/news/2018/07/wordpress-4-9-7-security-and-maintenance-release/
  241. Reference: https://www.wordfence.com/blog/2018/07/details-of-an-additional-file-deletion-vulnerability-patched-in-wordpress-4-9-7/
  242. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12895
  243.  
  244. [+] WordPress theme in use: default - v1.6
  245.  
  246. [+] Name: default - v1.6
  247. | Last updated: 2010-06-14T00:00:00.000Z
  248. | Location: http://10.11.1.251/wp/wp-content/themes/default/
  249. [!] The version is out of date, the latest version is 1.7.2
  250. | Style URL: http://10.11.1.251/wp/wp-content/themes/default/style.css
  251. | Theme Name: WordPress Default
  252. | Theme URI: http://wordpress.org/
  253. | Description: The default WordPress theme based on the famous <a href="http://binarybonsai.com/kubrick/">Kubric...
  254. | Author: Michael Heilemann
  255. | Author URI: http://binarybonsai.com/
  256.  
  257. [+] Enumerating plugins from passive detection ...
  258. | 1 plugin found:
  259.  
  260. [+] Name: wp-forum
  261. | Location: http://10.11.1.251/wp/wp-content/plugins/wp-forum/
  262. [!] Directory listing is enabled: http://10.11.1.251/wp/wp-content/plugins/wp-forum/
  263.  
  264. [!] We could not determine the version installed. All of the past known vulnerabilities will be output to allow you to do your own manual investigation.
  265.  
  266. [!] Title: wp-forum - SQL Injection
  267. Reference: https://wpvulndb.com/vulnerabilities/6732
  268. Reference: http://cxsecurity.com/issue/WLB-2013020035
  269.  
  270. [+] Finished: Tue Nov 26 09:15:43 2019
  271. [+] Elapsed time: 00:00:07
  272. [+] Requests made: 78
  273. [+] Memory used: 37.016 MB
  274. root@kali:~/Desktop#
Advertisement
Add Comment
Please, Sign In to add comment