Slupik98

[WP AUDYT] kamillotv.wex.pl

Dec 16th, 2017
175
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 50.33 KB | None | 0 0
  1. <pre><font color="#4E9A06">[+]</font> URL: http://kamillotv.wex.pl/
  2. <font color="#4E9A06">[+]</font> Started: Sat Dec 16 23:56:06 2017
  3.  
  4. <font color="#4E9A06">[+]</font> robots.txt available under: &apos;http://kamillotv.wex.pl/robots.txt&apos;
  5. <font color="#C4A000">[!]</font> The WordPress &apos;http://kamillotv.wex.pl/readme.html&apos; file exists exposing a version number
  6. <font color="#4E9A06">[+]</font> Interesting header: SERVER: nginx
  7. <font color="#4E9A06">[+]</font> Interesting header: X-CACHE-STATUS: HIT
  8. <font color="#4E9A06">[+]</font> XML-RPC Interface available under: http://kamillotv.wex.pl/xmlrpc.php
  9.  
  10. <font color="#4E9A06">[+]</font> WordPress version 4.3.1 (Released on 2015-09-15) identified from advanced fingerprinting, meta generator, rss generator, rdf generator, atom generator, readme, links opml
  11. <font color="#CC0000">[!]</font> 44 vulnerabilities identified from the version number
  12.  
  13. <font color="#CC0000">[!]</font> Title: WordPress 3.7-4.4 - Authenticated Cross-Site Scripting (XSS)
  14. Reference: https://wpvulndb.com/vulnerabilities/8358
  15. Reference: https://wordpress.org/news/2016/01/wordpress-4-4-1-security-and-maintenance-release/
  16. Reference: https://github.com/WordPress/WordPress/commit/7ab65139c6838910426567849c7abed723932b87
  17. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1564
  18. <font color="#3465A4">[i]</font> Fixed in: 4.3.2
  19.  
  20. <font color="#CC0000">[!]</font> Title: WordPress 3.7-4.4 - Authenticated Cross-Site Scripting (XSS)
  21. Reference: https://wpvulndb.com/vulnerabilities/8358
  22. Reference: https://wordpress.org/news/2016/01/wordpress-4-4-1-security-and-maintenance-release/
  23. Reference: https://github.com/WordPress/WordPress/commit/7ab65139c6838910426567849c7abed723932b87
  24. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1564
  25. <font color="#3465A4">[i]</font> Fixed in: 4.3.2
  26.  
  27. <font color="#CC0000">[!]</font> Title: WordPress 3.7-4.4.1 - Local URIs Server Side Request Forgery (SSRF)
  28. Reference: https://wpvulndb.com/vulnerabilities/8376
  29. Reference: https://wordpress.org/news/2016/02/wordpress-4-4-2-security-and-maintenance-release/
  30. Reference: https://core.trac.wordpress.org/changeset/36435
  31. Reference: https://hackerone.com/reports/110801
  32. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2222
  33. <font color="#3465A4">[i]</font> Fixed in: 4.3.3
  34.  
  35. <font color="#CC0000">[!]</font> Title: WordPress 3.7-4.4.1 - Open Redirect
  36. Reference: https://wpvulndb.com/vulnerabilities/8377
  37. Reference: https://wordpress.org/news/2016/02/wordpress-4-4-2-security-and-maintenance-release/
  38. Reference: https://core.trac.wordpress.org/changeset/36444
  39. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2221
  40. <font color="#3465A4">[i]</font> Fixed in: 4.3.3
  41.  
  42. <font color="#CC0000">[!]</font> Title: WordPress &lt;= 4.4.2 - SSRF Bypass using Octal &amp; Hexedecimal IP addresses
  43. Reference: https://wpvulndb.com/vulnerabilities/8473
  44. Reference: https://codex.wordpress.org/Version_4.5
  45. Reference: https://github.com/WordPress/WordPress/commit/af9f0520875eda686fd13a427fd3914d7aded049
  46. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4029
  47. <font color="#3465A4">[i]</font> Fixed in: 4.5
  48.  
  49. <font color="#CC0000">[!]</font> Title: WordPress &lt;= 4.4.2 - Reflected XSS in Network Settings
  50. Reference: https://wpvulndb.com/vulnerabilities/8474
  51. Reference: https://codex.wordpress.org/Version_4.5
  52. Reference: https://github.com/WordPress/WordPress/commit/cb2b3ed3c7d68f6505bfb5c90257e6aaa3e5fcb9
  53. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6634
  54. <font color="#3465A4">[i]</font> Fixed in: 4.5
  55.  
  56. <font color="#CC0000">[!]</font> Title: WordPress &lt;= 4.4.2 - Script Compression Option CSRF
  57. Reference: https://wpvulndb.com/vulnerabilities/8475
  58. Reference: https://codex.wordpress.org/Version_4.5
  59. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6635
  60. <font color="#3465A4">[i]</font> Fixed in: 4.5
  61.  
  62. <font color="#CC0000">[!]</font> Title: WordPress 4.2-4.5.1 - MediaElement.js Reflected Cross-Site Scripting (XSS)
  63. Reference: https://wpvulndb.com/vulnerabilities/8488
  64. Reference: https://wordpress.org/news/2016/05/wordpress-4-5-2/
  65. Reference: https://github.com/WordPress/WordPress/commit/a493dc0ab5819c8b831173185f1334b7c3e02e36
  66. Reference: https://gist.github.com/cure53/df34ea68c26441f3ae98f821ba1feb9c
  67. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4567
  68. <font color="#3465A4">[i]</font> Fixed in: 4.5.2
  69.  
  70. <font color="#CC0000">[!]</font> Title: WordPress &lt;= 4.5.1 - Pupload Same Origin Method Execution (SOME)
  71. Reference: https://wpvulndb.com/vulnerabilities/8489
  72. Reference: https://wordpress.org/news/2016/05/wordpress-4-5-2/
  73. Reference: https://github.com/WordPress/WordPress/commit/c33e975f46a18f5ad611cf7e7c24398948cecef8
  74. Reference: https://gist.github.com/cure53/09a81530a44f6b8173f545accc9ed07e
  75. Reference: http://avlidienbrunn.com/wp_some_loader.php
  76. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4566
  77. <font color="#3465A4">[i]</font> Fixed in: 4.3.4
  78.  
  79. <font color="#CC0000">[!]</font> Title: WordPress 4.2-4.5.2 - Authenticated Attachment Name Stored XSS
  80. Reference: https://wpvulndb.com/vulnerabilities/8518
  81. Reference: https://wordpress.org/news/2016/06/wordpress-4-5-3/
  82. Reference: https://github.com/WordPress/WordPress/commit/4372cdf45d0f49c74bbd4d60db7281de83e32648
  83. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5833
  84. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5834
  85. <font color="#3465A4">[i]</font> Fixed in: 4.3.5
  86.  
  87. <font color="#CC0000">[!]</font> Title: WordPress 3.6-4.5.2 - Authenticated Revision History Information Disclosure
  88. Reference: https://wpvulndb.com/vulnerabilities/8519
  89. Reference: https://wordpress.org/news/2016/06/wordpress-4-5-3/
  90. Reference: https://github.com/WordPress/WordPress/commit/a2904cc3092c391ac7027bc87f7806953d1a25a1
  91. Reference: https://www.wordfence.com/blog/2016/06/wordpress-core-vulnerability-bypass-password-protected-posts/
  92. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5835
  93. <font color="#3465A4">[i]</font> Fixed in: 4.3.5
  94.  
  95. <font color="#CC0000">[!]</font> Title: WordPress 2.6.0-4.5.2 - Unauthorized Category Removal from Post
  96. Reference: https://wpvulndb.com/vulnerabilities/8520
  97. Reference: https://wordpress.org/news/2016/06/wordpress-4-5-3/
  98. Reference: https://github.com/WordPress/WordPress/commit/6d05c7521baa980c4efec411feca5e7fab6f307c
  99. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5837
  100. <font color="#3465A4">[i]</font> Fixed in: 4.3.5
  101.  
  102. <font color="#CC0000">[!]</font> Title: WordPress 2.5-4.6 - Authenticated Stored Cross-Site Scripting via Image Filename
  103. Reference: https://wpvulndb.com/vulnerabilities/8615
  104. Reference: https://wordpress.org/news/2016/09/wordpress-4-6-1-security-and-maintenance-release/
  105. Reference: https://github.com/WordPress/WordPress/commit/c9e60dab176635d4bfaaf431c0ea891e4726d6e0
  106. Reference: https://sumofpwn.nl/advisory/2016/persistent_cross_site_scripting_vulnerability_in_wordpress_due_to_unsafe_processing_of_file_names.html
  107. Reference: http://seclists.org/fulldisclosure/2016/Sep/6
  108. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7168
  109. <font color="#3465A4">[i]</font> Fixed in: 4.3.6
  110.  
  111. <font color="#CC0000">[!]</font> Title: WordPress 2.8-4.6 - Path Traversal in Upgrade Package Uploader
  112. Reference: https://wpvulndb.com/vulnerabilities/8616
  113. Reference: https://wordpress.org/news/2016/09/wordpress-4-6-1-security-and-maintenance-release/
  114. Reference: https://github.com/WordPress/WordPress/commit/54720a14d85bc1197ded7cb09bd3ea790caa0b6e
  115. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7169
  116. <font color="#3465A4">[i]</font> Fixed in: 4.3.6
  117.  
  118. <font color="#CC0000">[!]</font> Title: WordPress 4.3-4.7 - Remote Code Execution (RCE) in PHPMailer
  119. Reference: https://wpvulndb.com/vulnerabilities/8714
  120. Reference: https://www.wordfence.com/blog/2016/12/phpmailer-vulnerability/
  121. Reference: https://github.com/PHPMailer/PHPMailer/wiki/About-the-CVE-2016-10033-and-CVE-2016-10045-vulnerabilities
  122. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
  123. Reference: https://github.com/WordPress/WordPress/commit/24767c76d359231642b0ab48437b64e8c6c7f491
  124. Reference: http://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10033-Vuln.html
  125. Reference: https://www.rapid7.com/db/modules/exploit/unix/webapp/wp_phpmailer_host_header
  126. <font color="#3465A4">[i]</font> Fixed in: 4.3.7
  127.  
  128. <font color="#CC0000">[!]</font> Title: WordPress 2.9-4.7 - Authenticated Cross-Site scripting (XSS) in update-core.php
  129. Reference: https://wpvulndb.com/vulnerabilities/8716
  130. Reference: https://github.com/WordPress/WordPress/blob/c9ea1de1441bb3bda133bf72d513ca9de66566c2/wp-admin/update-core.php
  131. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
  132. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5488
  133. <font color="#3465A4">[i]</font> Fixed in: 4.3.7
  134.  
  135. <font color="#CC0000">[!]</font> Title: WordPress 3.4-4.7 - Stored Cross-Site Scripting (XSS) via Theme Name fallback
  136. Reference: https://wpvulndb.com/vulnerabilities/8718
  137. Reference: https://www.mehmetince.net/low-severity-wordpress/
  138. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
  139. Reference: https://github.com/WordPress/WordPress/commit/ce7fb2934dd111e6353784852de8aea2a938b359
  140. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5490
  141. <font color="#3465A4">[i]</font> Fixed in: 4.3.7
  142.  
  143. <font color="#CC0000">[!]</font> Title: WordPress &lt;= 4.7 - Post via Email Checks mail.example.com by Default
  144. Reference: https://wpvulndb.com/vulnerabilities/8719
  145. Reference: https://github.com/WordPress/WordPress/commit/061e8788814ac87706d8b95688df276fe3c8596a
  146. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
  147. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5491
  148. <font color="#3465A4">[i]</font> Fixed in: 4.3.7
  149.  
  150. <font color="#CC0000">[!]</font> Title: WordPress 2.8-4.7 - Accessibility Mode Cross-Site Request Forgery (CSRF)
  151. Reference: https://wpvulndb.com/vulnerabilities/8720
  152. Reference: https://github.com/WordPress/WordPress/commit/03e5c0314aeffe6b27f4b98fef842bf0fb00c733
  153. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
  154. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5492
  155. <font color="#3465A4">[i]</font> Fixed in: 4.3.7
  156.  
  157. <font color="#CC0000">[!]</font> Title: WordPress 3.0-4.7 - Cryptographically Weak Pseudo-Random Number Generator (PRNG)
  158. Reference: https://wpvulndb.com/vulnerabilities/8721
  159. Reference: https://github.com/WordPress/WordPress/commit/cea9e2dc62abf777e06b12ec4ad9d1aaa49b29f4
  160. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
  161. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5493
  162. <font color="#3465A4">[i]</font> Fixed in: 4.3.7
  163.  
  164. <font color="#CC0000">[!]</font> Title: WordPress 4.2.0-4.7.1 - Press This UI Available to Unauthorised Users
  165. Reference: https://wpvulndb.com/vulnerabilities/8729
  166. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/
  167. Reference: https://github.com/WordPress/WordPress/commit/21264a31e0849e6ff793a06a17de877dd88ea454
  168. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5610
  169. <font color="#3465A4">[i]</font> Fixed in: 4.3.8
  170.  
  171. <font color="#CC0000">[!]</font> Title: WordPress 3.5-4.7.1 - WP_Query SQL Injection
  172. Reference: https://wpvulndb.com/vulnerabilities/8730
  173. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/
  174. Reference: https://github.com/WordPress/WordPress/commit/85384297a60900004e27e417eac56d24267054cb
  175. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5611
  176. <font color="#3465A4">[i]</font> Fixed in: 4.3.8
  177.  
  178. <font color="#CC0000">[!]</font> Title: WordPress 4.3.0-4.7.1 - Cross-Site Scripting (XSS) in posts list table
  179. Reference: https://wpvulndb.com/vulnerabilities/8731
  180. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/
  181. Reference: https://github.com/WordPress/WordPress/commit/4482f9207027de8f36630737ae085110896ea849
  182. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5612
  183. <font color="#3465A4">[i]</font> Fixed in: 4.3.8
  184.  
  185. <font color="#CC0000">[!]</font> Title: WordPress 3.6.0-4.7.2 - Authenticated Cross-Site Scripting (XSS) via Media File Metadata
  186. Reference: https://wpvulndb.com/vulnerabilities/8765
  187. Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
  188. Reference: https://github.com/WordPress/WordPress/commit/28f838ca3ee205b6f39cd2bf23eb4e5f52796bd7
  189. Reference: https://sumofpwn.nl/advisory/2016/wordpress_audio_playlist_functionality_is_affected_by_cross_site_scripting.html
  190. Reference: http://seclists.org/oss-sec/2017/q1/563
  191. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6814
  192. <font color="#3465A4">[i]</font> Fixed in: 4.3.9
  193.  
  194. <font color="#CC0000">[!]</font> Title: WordPress 2.8.1-4.7.2 - Control Characters in Redirect URL Validation
  195. Reference: https://wpvulndb.com/vulnerabilities/8766
  196. Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
  197. Reference: https://github.com/WordPress/WordPress/commit/288cd469396cfe7055972b457eb589cea51ce40e
  198. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6815
  199. <font color="#3465A4">[i]</font> Fixed in: 4.3.9
  200.  
  201. <font color="#CC0000">[!]</font> Title: WordPress 4.0-4.7.2 - Authenticated Stored Cross-Site Scripting (XSS) in YouTube URL Embeds
  202. Reference: https://wpvulndb.com/vulnerabilities/8768
  203. Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
  204. Reference: https://github.com/WordPress/WordPress/commit/419c8d97ce8df7d5004ee0b566bc5e095f0a6ca8
  205. Reference: https://blog.sucuri.net/2017/03/stored-xss-in-wordpress-core.html
  206. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6817
  207. <font color="#3465A4">[i]</font> Fixed in: 4.3.9
  208.  
  209. <font color="#CC0000">[!]</font> Title: WordPress 4.2-4.7.2 - Press This CSRF DoS
  210. Reference: https://wpvulndb.com/vulnerabilities/8770
  211. Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
  212. Reference: https://github.com/WordPress/WordPress/commit/263831a72d08556bc2f3a328673d95301a152829
  213. Reference: https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_wordpress_press_this_function_allows_dos.html
  214. Reference: http://seclists.org/oss-sec/2017/q1/562
  215. Reference: https://hackerone.com/reports/153093
  216. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6819
  217. <font color="#3465A4">[i]</font> Fixed in: 4.3.9
  218.  
  219. <font color="#CC0000">[!]</font> Title: WordPress 2.3-4.8.3 - Host Header Injection in Password Reset
  220. Reference: https://wpvulndb.com/vulnerabilities/8807
  221. Reference: https://exploitbox.io/vuln/WordPress-Exploit-4-7-Unauth-Password-Reset-0day-CVE-2017-8295.html
  222. Reference: http://blog.dewhurstsecurity.com/2017/05/04/exploitbox-wordpress-security-advisories.html
  223. Reference: https://core.trac.wordpress.org/ticket/25239
  224. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8295
  225.  
  226. <font color="#CC0000">[!]</font> Title: WordPress 2.7.0-4.7.4 - Insufficient Redirect Validation
  227. Reference: https://wpvulndb.com/vulnerabilities/8815
  228. Reference: https://github.com/WordPress/WordPress/commit/76d77e927bb4d0f87c7262a50e28d84e01fd2b11
  229. Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
  230. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9066
  231. <font color="#3465A4">[i]</font> Fixed in: 4.3.11
  232.  
  233. <font color="#CC0000">[!]</font> Title: WordPress 2.5.0-4.7.4 - Post Meta Data Values Improper Handling in XML-RPC
  234. Reference: https://wpvulndb.com/vulnerabilities/8816
  235. Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
  236. Reference: https://github.com/WordPress/WordPress/commit/3d95e3ae816f4d7c638f40d3e936a4be19724381
  237. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9062
  238. <font color="#3465A4">[i]</font> Fixed in: 4.3.11
  239.  
  240. <font color="#CC0000">[!]</font> Title: WordPress 3.4.0-4.7.4 - XML-RPC Post Meta Data Lack of Capability Checks
  241. Reference: https://wpvulndb.com/vulnerabilities/8817
  242. Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
  243. Reference: https://github.com/WordPress/WordPress/commit/e88a48a066ab2200ce3091b131d43e2fab2460a4
  244. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9065
  245. <font color="#3465A4">[i]</font> Fixed in: 4.3.11
  246.  
  247. <font color="#CC0000">[!]</font> Title: WordPress 2.5.0-4.7.4 - Filesystem Credentials Dialog CSRF
  248. Reference: https://wpvulndb.com/vulnerabilities/8818
  249. Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
  250. Reference: https://github.com/WordPress/WordPress/commit/38347d7c580be4cdd8476e4bbc653d5c79ed9b67
  251. Reference: https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_wordpress_connection_information.html
  252. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9064
  253. <font color="#3465A4">[i]</font> Fixed in: 4.3.11
  254.  
  255. <font color="#CC0000">[!]</font> Title: WordPress 3.3-4.7.4 - Large File Upload Error XSS
  256. Reference: https://wpvulndb.com/vulnerabilities/8819
  257. Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
  258. Reference: https://github.com/WordPress/WordPress/commit/8c7ea71edbbffca5d9766b7bea7c7f3722ffafa6
  259. Reference: https://hackerone.com/reports/203515
  260. Reference: https://hackerone.com/reports/203515
  261. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9061
  262. <font color="#3465A4">[i]</font> Fixed in: 4.3.11
  263.  
  264. <font color="#CC0000">[!]</font> Title: WordPress 3.4.0-4.7.4 - Customizer XSS &amp; CSRF
  265. Reference: https://wpvulndb.com/vulnerabilities/8820
  266. Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
  267. Reference: https://github.com/WordPress/WordPress/commit/3d10fef22d788f29aed745b0f5ff6f6baea69af3
  268. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9063
  269. <font color="#3465A4">[i]</font> Fixed in: 4.3.11
  270.  
  271. <font color="#CC0000">[!]</font> Title: WordPress 2.3.0-4.8.1 - $wpdb-&gt;prepare() potential SQL Injection
  272. Reference: https://wpvulndb.com/vulnerabilities/8905
  273. Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  274. Reference: https://github.com/WordPress/WordPress/commit/70b21279098fc973eae803693c0705a548128e48
  275. Reference: https://github.com/WordPress/WordPress/commit/fc930d3daed1c3acef010d04acc2c5de93cd18ec
  276. <font color="#3465A4">[i]</font> Fixed in: 4.3.12
  277.  
  278. <font color="#CC0000">[!]</font> Title: WordPress 2.3.0-4.7.4 - Authenticated SQL injection
  279. Reference: https://wpvulndb.com/vulnerabilities/8906
  280. Reference: https://medium.com/websec/wordpress-sqli-bbb2afcc8e94
  281. Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  282. Reference: https://github.com/WordPress/WordPress/commit/70b21279098fc973eae803693c0705a548128e48
  283. Reference: https://wpvulndb.com/vulnerabilities/8905
  284. <font color="#3465A4">[i]</font> Fixed in: 4.7.5
  285.  
  286. <font color="#CC0000">[!]</font> Title: WordPress 2.9.2-4.8.1 - Open Redirect
  287. Reference: https://wpvulndb.com/vulnerabilities/8910
  288. Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  289. Reference: https://core.trac.wordpress.org/changeset/41398
  290. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14725
  291. <font color="#3465A4">[i]</font> Fixed in: 4.3.12
  292.  
  293. <font color="#CC0000">[!]</font> Title: WordPress 3.0-4.8.1 - Path Traversal in Unzipping
  294. Reference: https://wpvulndb.com/vulnerabilities/8911
  295. Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  296. Reference: https://core.trac.wordpress.org/changeset/41457
  297. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14719
  298. <font color="#3465A4">[i]</font> Fixed in: 4.3.12
  299.  
  300. <font color="#CC0000">[!]</font> Title: WordPress 4.2.3-4.8.1 - Authenticated Cross-Site Scripting (XSS) in Visual Editor
  301. Reference: https://wpvulndb.com/vulnerabilities/8914
  302. Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  303. Reference: https://core.trac.wordpress.org/changeset/41395
  304. Reference: https://blog.sucuri.net/2017/09/stored-cross-site-scripting-vulnerability-in-wordpress-4-8-1.html
  305. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14726
  306. <font color="#3465A4">[i]</font> Fixed in: 4.3.12
  307.  
  308. <font color="#CC0000">[!]</font> Title: WordPress &lt;= 4.8.2 - $wpdb-&gt;prepare() Weakness
  309. Reference: https://wpvulndb.com/vulnerabilities/8941
  310. Reference: https://wordpress.org/news/2017/10/wordpress-4-8-3-security-release/
  311. Reference: https://github.com/WordPress/WordPress/commit/a2693fd8602e3263b5925b9d799ddd577202167d
  312. Reference: https://twitter.com/ircmaxell/status/923662170092638208
  313. Reference: https://blog.ircmaxell.com/2017/10/disclosure-wordpress-wpdb-sql-injection-technical.html
  314. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16510
  315. <font color="#3465A4">[i]</font> Fixed in: 4.3.13
  316.  
  317. <font color="#CC0000">[!]</font> Title: WordPress 2.8.6-4.9 - Authenticated JavaScript File Upload
  318. Reference: https://wpvulndb.com/vulnerabilities/8966
  319. Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  320. Reference: https://github.com/WordPress/WordPress/commit/67d03a98c2cae5f41843c897f206adde299b0509
  321. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17092
  322. <font color="#3465A4">[i]</font> Fixed in: 4.3.14
  323.  
  324. <font color="#CC0000">[!]</font> Title: WordPress 1.5.0-4.9 - RSS and Atom Feed Escaping
  325. Reference: https://wpvulndb.com/vulnerabilities/8967
  326. Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  327. Reference: https://github.com/WordPress/WordPress/commit/f1de7e42df29395c3314bf85bff3d1f4f90541de
  328. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17094
  329. <font color="#3465A4">[i]</font> Fixed in: 4.3.14
  330.  
  331. <font color="#CC0000">[!]</font> Title: WordPress 4.3.0-4.9 - HTML Language Attribute Escaping
  332. Reference: https://wpvulndb.com/vulnerabilities/8968
  333. Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  334. Reference: https://github.com/WordPress/WordPress/commit/3713ac5ebc90fb2011e98dfd691420f43da6c09a
  335. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17093
  336. <font color="#3465A4">[i]</font> Fixed in: 4.3.14
  337.  
  338. <font color="#CC0000">[!]</font> Title: WordPress 3.7-4.9 - &apos;newbloguser&apos; Key Weak Hashing
  339. Reference: https://wpvulndb.com/vulnerabilities/8969
  340. Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  341. Reference: https://github.com/WordPress/WordPress/commit/eaf1cfdc1fe0bdffabd8d879c591b864d833326c
  342. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17091
  343. <font color="#3465A4">[i]</font> Fixed in: 4.3.14
  344.  
  345. <font color="#4E9A06">[+]</font> WordPress theme in use: twentyfourteen - v1.5
  346.  
  347. <font color="#4E9A06">[+]</font> Name: twentyfourteen - v1.5
  348. | Last updated: 2017-11-16T00:00:00.000Z
  349. | Location: http://kamillotv.wex.pl/wp-content/themes/twentyfourteen/
  350. | Readme: http://kamillotv.wex.pl/wp-content/themes/twentyfourteen/readme.txt
  351. <font color="#C4A000">[!]</font> The version is out of date, the latest version is 2.1
  352. | Style URL: http://kamillotv.wex.pl/wp-content/themes/twentyfourteen/style.css
  353. | Theme Name: Twenty Fourteen
  354. | Theme URI: https://wordpress.org/themes/twentyfourteen/
  355. | Description: In 2014, our default theme lets you create a responsive magazine website with a sleek, modern des...
  356. | Author: the WordPress team
  357. | Author URI: https://wordpress.org/
  358.  
  359. <font color="#4E9A06">[+]</font> Enumerating plugins from passive detection ...
  360. | 1 plugin found:
  361.  
  362. <font color="#4E9A06">[+]</font> Name: wordpress-seo - v2.3.5
  363. | Last updated: 2017-12-05T11:24:00.000Z
  364. | Location: http://kamillotv.wex.pl/wp-content/plugins/wordpress-seo/
  365. | Readme: http://kamillotv.wex.pl/wp-content/plugins/wordpress-seo/readme.txt
  366. | Changelog: http://kamillotv.wex.pl/wp-content/plugins/wordpress-seo/changelog.txt
  367. <font color="#C4A000">[!]</font> The version is out of date, the latest version is 5.9.1
  368.  
  369. <font color="#CC0000">[!]</font> Title: Yoast SEO &lt;= 3.2.4 - Subscriber Settings Sensitive Data Exposure
  370. Reference: https://wpvulndb.com/vulnerabilities/8487
  371. Reference: https://www.wordfence.com/blog/2016/05/yoast-seo-vulnerability/
  372. <font color="#3465A4">[i]</font> Fixed in: 3.2.5
  373.  
  374. <font color="#CC0000">[!]</font> Title: Yoast SEO &lt;= 3.2.5 - Unspecified Cross-Site Scripting (XSS)
  375. Reference: https://wpvulndb.com/vulnerabilities/8569
  376. Reference: https://wordpress.org/plugins/wordpress-seo/changelog/
  377. <font color="#3465A4">[i]</font> Fixed in: 3.3.0
  378.  
  379. <font color="#CC0000">[!]</font> Title: Yoast SEO &lt;= 3.4.0 - Authenticated Stored Cross-Site Scripting (XSS)
  380. Reference: https://wpvulndb.com/vulnerabilities/8583
  381. Reference: https://plugins.trac.wordpress.org/changeset/1466243/wordpress-seo
  382. <font color="#3465A4">[i]</font> Fixed in: 3.4.1
  383.  
  384. <font color="#CC0000">[!]</font> Title: Yoast SEO &lt;= 5.7.1 - Unauthenticated Cross-Site Scripting (XSS)
  385. Reference: https://wpvulndb.com/vulnerabilities/8960
  386. Reference: https://plugins.trac.wordpress.org/changeset/1766831/wordpress-seo/trunk/admin/google_search_console/class-gsc-table.php
  387. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16842
  388. <font color="#3465A4">[i]</font> Fixed in: 5.8
  389.  
  390. <font color="#4E9A06">[+]</font> Enumerating usernames ...
  391. <font color="#4E9A06">[+]</font> Identified the following 1 user/s:
  392. +----+-------+---------------------------------+
  393. | Id | Login | Name |
  394. +----+-------+---------------------------------+
  395. | 1 | admin | admin, Autor w serwisie Kamillo |
  396. +----+-------+---------------------------------+
  397. <font color="#C4A000">[!]</font> Default first WordPress username &apos;admin&apos; is still used
  398.  
  399. <font color="#4E9A06">[+]</font> Finished: Sat Dec 16 23:56:31 2017
  400. <font color="#4E9A06">[+]</font> Requests Done: 93
  401. <font color="#4E9A06">[+]</font> Memory used: 36.223 MB
  402. <font color="#4E9A06">[+]</font> Elapsed time: 00:00:24
  403. </pre>
  404.  
  405.  
  406.  
  407.  
  408.  
  409.  
  410.  
  411. [+] robots.txt available under: 'http://kamillotv.wex.pl/robots.txt'
  412. [!] The WordPress 'http://kamillotv.wex.pl/readme.html' file exists exposing a version number
  413. [+] Interesting header: SERVER: nginx
  414. [+] Interesting header: X-CACHE-STATUS: HIT
  415. [+] XML-RPC Interface available under: http://kamillotv.wex.pl/xmlrpc.php
  416.  
  417. [+] WordPress version 4.3.1 (Released on 2015-09-15) identified from advanced fingerprinting, meta generator, rss generator, rdf generator, atom generator, readme, links opml
  418. [!] 44 vulnerabilities identified from the version number
  419.  
  420. [!] Title: WordPress 3.7-4.4 - Authenticated Cross-Site Scripting (XSS)
  421. Reference: https://wpvulndb.com/vulnerabilities/8358
  422. Reference: https://wordpress.org/news/2016/01/wordpress-4-4-1-security-and-maintenance-release/
  423. Reference: https://github.com/WordPress/WordPress/commit/7ab65139c6838910426567849c7abed723932b87
  424. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1564
  425. [i] Fixed in: 4.3.2
  426.  
  427. [!] Title: WordPress 3.7-4.4 - Authenticated Cross-Site Scripting (XSS)
  428. Reference: https://wpvulndb.com/vulnerabilities/8358
  429. Reference: https://wordpress.org/news/2016/01/wordpress-4-4-1-security-and-maintenance-release/
  430. Reference: https://github.com/WordPress/WordPress/commit/7ab65139c6838910426567849c7abed723932b87
  431. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1564
  432. [i] Fixed in: 4.3.2
  433.  
  434. [!] Title: WordPress 3.7-4.4.1 - Local URIs Server Side Request Forgery (SSRF)
  435. Reference: https://wpvulndb.com/vulnerabilities/8376
  436. Reference: https://wordpress.org/news/2016/02/wordpress-4-4-2-security-and-maintenance-release/
  437. Reference: https://core.trac.wordpress.org/changeset/36435
  438. Reference: https://hackerone.com/reports/110801
  439. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2222
  440. [i] Fixed in: 4.3.3
  441.  
  442. [!] Title: WordPress 3.7-4.4.1 - Open Redirect
  443. Reference: https://wpvulndb.com/vulnerabilities/8377
  444. Reference: https://wordpress.org/news/2016/02/wordpress-4-4-2-security-and-maintenance-release/
  445. Reference: https://core.trac.wordpress.org/changeset/36444
  446. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2221
  447. [i] Fixed in: 4.3.3
  448.  
  449. [!] Title: WordPress <= 4.4.2 - SSRF Bypass using Octal & Hexedecimal IP addresses
  450. Reference: https://wpvulndb.com/vulnerabilities/8473
  451. Reference: https://codex.wordpress.org/Version_4.5
  452. Reference: https://github.com/WordPress/WordPress/commit/af9f0520875eda686fd13a427fd3914d7aded049
  453. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4029
  454. [i] Fixed in: 4.5
  455.  
  456. [!] Title: WordPress <= 4.4.2 - Reflected XSS in Network Settings
  457. Reference: https://wpvulndb.com/vulnerabilities/8474
  458. Reference: https://codex.wordpress.org/Version_4.5
  459. Reference: https://github.com/WordPress/WordPress/commit/cb2b3ed3c7d68f6505bfb5c90257e6aaa3e5fcb9
  460. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6634
  461. [i] Fixed in: 4.5
  462.  
  463. [!] Title: WordPress <= 4.4.2 - Script Compression Option CSRF
  464. Reference: https://wpvulndb.com/vulnerabilities/8475
  465. Reference: https://codex.wordpress.org/Version_4.5
  466. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6635
  467. [i] Fixed in: 4.5
  468.  
  469. [!] Title: WordPress 4.2-4.5.1 - MediaElement.js Reflected Cross-Site Scripting (XSS)
  470. Reference: https://wpvulndb.com/vulnerabilities/8488
  471. Reference: https://wordpress.org/news/2016/05/wordpress-4-5-2/
  472. Reference: https://github.com/WordPress/WordPress/commit/a493dc0ab5819c8b831173185f1334b7c3e02e36
  473. Reference: https://gist.github.com/cure53/df34ea68c26441f3ae98f821ba1feb9c
  474. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4567
  475. [i] Fixed in: 4.5.2
  476.  
  477. [!] Title: WordPress <= 4.5.1 - Pupload Same Origin Method Execution (SOME)
  478. Reference: https://wpvulndb.com/vulnerabilities/8489
  479. Reference: https://wordpress.org/news/2016/05/wordpress-4-5-2/
  480. Reference: https://github.com/WordPress/WordPress/commit/c33e975f46a18f5ad611cf7e7c24398948cecef8
  481. Reference: https://gist.github.com/cure53/09a81530a44f6b8173f545accc9ed07e
  482. Reference: http://avlidienbrunn.com/wp_some_loader.php
  483. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4566
  484. [i] Fixed in: 4.3.4
  485.  
  486. [!] Title: WordPress 4.2-4.5.2 - Authenticated Attachment Name Stored XSS
  487. Reference: https://wpvulndb.com/vulnerabilities/8518
  488. Reference: https://wordpress.org/news/2016/06/wordpress-4-5-3/
  489. Reference: https://github.com/WordPress/WordPress/commit/4372cdf45d0f49c74bbd4d60db7281de83e32648
  490. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5833
  491. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5834
  492. [i] Fixed in: 4.3.5
  493.  
  494. [!] Title: WordPress 3.6-4.5.2 - Authenticated Revision History Information Disclosure
  495. Reference: https://wpvulndb.com/vulnerabilities/8519
  496. Reference: https://wordpress.org/news/2016/06/wordpress-4-5-3/
  497. Reference: https://github.com/WordPress/WordPress/commit/a2904cc3092c391ac7027bc87f7806953d1a25a1
  498. Reference: https://www.wordfence.com/blog/2016/06/wordpress-core-vulnerability-bypass-password-protected-posts/
  499. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5835
  500. [i] Fixed in: 4.3.5
  501.  
  502. [!] Title: WordPress 2.6.0-4.5.2 - Unauthorized Category Removal from Post
  503. Reference: https://wpvulndb.com/vulnerabilities/8520
  504. Reference: https://wordpress.org/news/2016/06/wordpress-4-5-3/
  505. Reference: https://github.com/WordPress/WordPress/commit/6d05c7521baa980c4efec411feca5e7fab6f307c
  506. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5837
  507. [i] Fixed in: 4.3.5
  508.  
  509. [!] Title: WordPress 2.5-4.6 - Authenticated Stored Cross-Site Scripting via Image Filename
  510. Reference: https://wpvulndb.com/vulnerabilities/8615
  511. Reference: https://wordpress.org/news/2016/09/wordpress-4-6-1-security-and-maintenance-release/
  512. Reference: https://github.com/WordPress/WordPress/commit/c9e60dab176635d4bfaaf431c0ea891e4726d6e0
  513. Reference: https://sumofpwn.nl/advisory/2016/persistent_cross_site_scripting_vulnerability_in_wordpress_due_to_unsafe_processing_of_file_names.html
  514. Reference: http://seclists.org/fulldisclosure/2016/Sep/6
  515. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7168
  516. [i] Fixed in: 4.3.6
  517.  
  518. [!] Title: WordPress 2.8-4.6 - Path Traversal in Upgrade Package Uploader
  519. Reference: https://wpvulndb.com/vulnerabilities/8616
  520. Reference: https://wordpress.org/news/2016/09/wordpress-4-6-1-security-and-maintenance-release/
  521. Reference: https://github.com/WordPress/WordPress/commit/54720a14d85bc1197ded7cb09bd3ea790caa0b6e
  522. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7169
  523. [i] Fixed in: 4.3.6
  524.  
  525. [!] Title: WordPress 4.3-4.7 - Remote Code Execution (RCE) in PHPMailer
  526. Reference: https://wpvulndb.com/vulnerabilities/8714
  527. Reference: https://www.wordfence.com/blog/2016/12/phpmailer-vulnerability/
  528. Reference: https://github.com/PHPMailer/PHPMailer/wiki/About-the-CVE-2016-10033-and-CVE-2016-10045-vulnerabilities
  529. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
  530. Reference: https://github.com/WordPress/WordPress/commit/24767c76d359231642b0ab48437b64e8c6c7f491
  531. Reference: http://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10033-Vuln.html
  532. Reference: https://www.rapid7.com/db/modules/exploit/unix/webapp/wp_phpmailer_host_header
  533. [i] Fixed in: 4.3.7
  534.  
  535. [!] Title: WordPress 2.9-4.7 - Authenticated Cross-Site scripting (XSS) in update-core.php
  536. Reference: https://wpvulndb.com/vulnerabilities/8716
  537. Reference: https://github.com/WordPress/WordPress/blob/c9ea1de1441bb3bda133bf72d513ca9de66566c2/wp-admin/update-core.php
  538. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
  539. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5488
  540. [i] Fixed in: 4.3.7
  541.  
  542. [!] Title: WordPress 3.4-4.7 - Stored Cross-Site Scripting (XSS) via Theme Name fallback
  543. Reference: https://wpvulndb.com/vulnerabilities/8718
  544. Reference: https://www.mehmetince.net/low-severity-wordpress/
  545. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
  546. Reference: https://github.com/WordPress/WordPress/commit/ce7fb2934dd111e6353784852de8aea2a938b359
  547. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5490
  548. [i] Fixed in: 4.3.7
  549.  
  550. [!] Title: WordPress <= 4.7 - Post via Email Checks mail.example.com by Default
  551. Reference: https://wpvulndb.com/vulnerabilities/8719
  552. Reference: https://github.com/WordPress/WordPress/commit/061e8788814ac87706d8b95688df276fe3c8596a
  553. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
  554. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5491
  555. [i] Fixed in: 4.3.7
  556.  
  557. [!] Title: WordPress 2.8-4.7 - Accessibility Mode Cross-Site Request Forgery (CSRF)
  558. Reference: https://wpvulndb.com/vulnerabilities/8720
  559. Reference: https://github.com/WordPress/WordPress/commit/03e5c0314aeffe6b27f4b98fef842bf0fb00c733
  560. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
  561. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5492
  562. [i] Fixed in: 4.3.7
  563.  
  564. [!] Title: WordPress 3.0-4.7 - Cryptographically Weak Pseudo-Random Number Generator (PRNG)
  565. Reference: https://wpvulndb.com/vulnerabilities/8721
  566. Reference: https://github.com/WordPress/WordPress/commit/cea9e2dc62abf777e06b12ec4ad9d1aaa49b29f4
  567. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
  568. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5493
  569. [i] Fixed in: 4.3.7
  570.  
  571. [!] Title: WordPress 4.2.0-4.7.1 - Press This UI Available to Unauthorised Users
  572. Reference: https://wpvulndb.com/vulnerabilities/8729
  573. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/
  574. Reference: https://github.com/WordPress/WordPress/commit/21264a31e0849e6ff793a06a17de877dd88ea454
  575. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5610
  576. [i] Fixed in: 4.3.8
  577.  
  578. [!] Title: WordPress 3.5-4.7.1 - WP_Query SQL Injection
  579. Reference: https://wpvulndb.com/vulnerabilities/8730
  580. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/
  581. Reference: https://github.com/WordPress/WordPress/commit/85384297a60900004e27e417eac56d24267054cb
  582. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5611
  583. [i] Fixed in: 4.3.8
  584.  
  585. [!] Title: WordPress 4.3.0-4.7.1 - Cross-Site Scripting (XSS) in posts list table
  586. Reference: https://wpvulndb.com/vulnerabilities/8731
  587. Reference: https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/
  588. Reference: https://github.com/WordPress/WordPress/commit/4482f9207027de8f36630737ae085110896ea849
  589. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5612
  590. [i] Fixed in: 4.3.8
  591.  
  592. [!] Title: WordPress 3.6.0-4.7.2 - Authenticated Cross-Site Scripting (XSS) via Media File Metadata
  593. Reference: https://wpvulndb.com/vulnerabilities/8765
  594. Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
  595. Reference: https://github.com/WordPress/WordPress/commit/28f838ca3ee205b6f39cd2bf23eb4e5f52796bd7
  596. Reference: https://sumofpwn.nl/advisory/2016/wordpress_audio_playlist_functionality_is_affected_by_cross_site_scripting.html
  597. Reference: http://seclists.org/oss-sec/2017/q1/563
  598. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6814
  599. [i] Fixed in: 4.3.9
  600.  
  601. [!] Title: WordPress 2.8.1-4.7.2 - Control Characters in Redirect URL Validation
  602. Reference: https://wpvulndb.com/vulnerabilities/8766
  603. Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
  604. Reference: https://github.com/WordPress/WordPress/commit/288cd469396cfe7055972b457eb589cea51ce40e
  605. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6815
  606. [i] Fixed in: 4.3.9
  607.  
  608. [!] Title: WordPress 4.0-4.7.2 - Authenticated Stored Cross-Site Scripting (XSS) in YouTube URL Embeds
  609. Reference: https://wpvulndb.com/vulnerabilities/8768
  610. Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
  611. Reference: https://github.com/WordPress/WordPress/commit/419c8d97ce8df7d5004ee0b566bc5e095f0a6ca8
  612. Reference: https://blog.sucuri.net/2017/03/stored-xss-in-wordpress-core.html
  613. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6817
  614. [i] Fixed in: 4.3.9
  615.  
  616. [!] Title: WordPress 4.2-4.7.2 - Press This CSRF DoS
  617. Reference: https://wpvulndb.com/vulnerabilities/8770
  618. Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
  619. Reference: https://github.com/WordPress/WordPress/commit/263831a72d08556bc2f3a328673d95301a152829
  620. Reference: https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_wordpress_press_this_function_allows_dos.html
  621. Reference: http://seclists.org/oss-sec/2017/q1/562
  622. Reference: https://hackerone.com/reports/153093
  623. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6819
  624. [i] Fixed in: 4.3.9
  625.  
  626. [!] Title: WordPress 2.3-4.8.3 - Host Header Injection in Password Reset
  627. Reference: https://wpvulndb.com/vulnerabilities/8807
  628. Reference: https://exploitbox.io/vuln/WordPress-Exploit-4-7-Unauth-Password-Reset-0day-CVE-2017-8295.html
  629. Reference: http://blog.dewhurstsecurity.com/2017/05/04/exploitbox-wordpress-security-advisories.html
  630. Reference: https://core.trac.wordpress.org/ticket/25239
  631. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8295
  632.  
  633. [!] Title: WordPress 2.7.0-4.7.4 - Insufficient Redirect Validation
  634. Reference: https://wpvulndb.com/vulnerabilities/8815
  635. Reference: https://github.com/WordPress/WordPress/commit/76d77e927bb4d0f87c7262a50e28d84e01fd2b11
  636. Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
  637. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9066
  638. [i] Fixed in: 4.3.11
  639.  
  640. [!] Title: WordPress 2.5.0-4.7.4 - Post Meta Data Values Improper Handling in XML-RPC
  641. Reference: https://wpvulndb.com/vulnerabilities/8816
  642. Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
  643. Reference: https://github.com/WordPress/WordPress/commit/3d95e3ae816f4d7c638f40d3e936a4be19724381
  644. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9062
  645. [i] Fixed in: 4.3.11
  646.  
  647. [!] Title: WordPress 3.4.0-4.7.4 - XML-RPC Post Meta Data Lack of Capability Checks
  648. Reference: https://wpvulndb.com/vulnerabilities/8817
  649. Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
  650. Reference: https://github.com/WordPress/WordPress/commit/e88a48a066ab2200ce3091b131d43e2fab2460a4
  651. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9065
  652. [i] Fixed in: 4.3.11
  653.  
  654. [!] Title: WordPress 2.5.0-4.7.4 - Filesystem Credentials Dialog CSRF
  655. Reference: https://wpvulndb.com/vulnerabilities/8818
  656. Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
  657. Reference: https://github.com/WordPress/WordPress/commit/38347d7c580be4cdd8476e4bbc653d5c79ed9b67
  658. Reference: https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_wordpress_connection_information.html
  659. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9064
  660. [i] Fixed in: 4.3.11
  661.  
  662. [!] Title: WordPress 3.3-4.7.4 - Large File Upload Error XSS
  663. Reference: https://wpvulndb.com/vulnerabilities/8819
  664. Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
  665. Reference: https://github.com/WordPress/WordPress/commit/8c7ea71edbbffca5d9766b7bea7c7f3722ffafa6
  666. Reference: https://hackerone.com/reports/203515
  667. Reference: https://hackerone.com/reports/203515
  668. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9061
  669. [i] Fixed in: 4.3.11
  670.  
  671. [!] Title: WordPress 3.4.0-4.7.4 - Customizer XSS & CSRF
  672. Reference: https://wpvulndb.com/vulnerabilities/8820
  673. Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
  674. Reference: https://github.com/WordPress/WordPress/commit/3d10fef22d788f29aed745b0f5ff6f6baea69af3
  675. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9063
  676. [i] Fixed in: 4.3.11
  677.  
  678. [!] Title: WordPress 2.3.0-4.8.1 - $wpdb->prepare() potential SQL Injection
  679. Reference: https://wpvulndb.com/vulnerabilities/8905
  680. Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  681. Reference: https://github.com/WordPress/WordPress/commit/70b21279098fc973eae803693c0705a548128e48
  682. Reference: https://github.com/WordPress/WordPress/commit/fc930d3daed1c3acef010d04acc2c5de93cd18ec
  683. [i] Fixed in: 4.3.12
  684.  
  685. [!] Title: WordPress 2.3.0-4.7.4 - Authenticated SQL injection
  686. Reference: https://wpvulndb.com/vulnerabilities/8906
  687. Reference: https://medium.com/websec/wordpress-sqli-bbb2afcc8e94
  688. Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  689. Reference: https://github.com/WordPress/WordPress/commit/70b21279098fc973eae803693c0705a548128e48
  690. Reference: https://wpvulndb.com/vulnerabilities/8905
  691. [i] Fixed in: 4.7.5
  692.  
  693. [!] Title: WordPress 2.9.2-4.8.1 - Open Redirect
  694. Reference: https://wpvulndb.com/vulnerabilities/8910
  695. Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  696. Reference: https://core.trac.wordpress.org/changeset/41398
  697. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14725
  698. [i] Fixed in: 4.3.12
  699.  
  700. [!] Title: WordPress 3.0-4.8.1 - Path Traversal in Unzipping
  701. Reference: https://wpvulndb.com/vulnerabilities/8911
  702. Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  703. Reference: https://core.trac.wordpress.org/changeset/41457
  704. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14719
  705. [i] Fixed in: 4.3.12
  706.  
  707. [!] Title: WordPress 4.2.3-4.8.1 - Authenticated Cross-Site Scripting (XSS) in Visual Editor
  708. Reference: https://wpvulndb.com/vulnerabilities/8914
  709. Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  710. Reference: https://core.trac.wordpress.org/changeset/41395
  711. Reference: https://blog.sucuri.net/2017/09/stored-cross-site-scripting-vulnerability-in-wordpress-4-8-1.html
  712. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14726
  713. [i] Fixed in: 4.3.12
  714.  
  715. [!] Title: WordPress <= 4.8.2 - $wpdb->prepare() Weakness
  716. Reference: https://wpvulndb.com/vulnerabilities/8941
  717. Reference: https://wordpress.org/news/2017/10/wordpress-4-8-3-security-release/
  718. Reference: https://github.com/WordPress/WordPress/commit/a2693fd8602e3263b5925b9d799ddd577202167d
  719. Reference: https://twitter.com/ircmaxell/status/923662170092638208
  720. Reference: https://blog.ircmaxell.com/2017/10/disclosure-wordpress-wpdb-sql-injection-technical.html
  721. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16510
  722. [i] Fixed in: 4.3.13
  723.  
  724. [!] Title: WordPress 2.8.6-4.9 - Authenticated JavaScript File Upload
  725. Reference: https://wpvulndb.com/vulnerabilities/8966
  726. Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  727. Reference: https://github.com/WordPress/WordPress/commit/67d03a98c2cae5f41843c897f206adde299b0509
  728. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17092
  729. [i] Fixed in: 4.3.14
  730.  
  731. [!] Title: WordPress 1.5.0-4.9 - RSS and Atom Feed Escaping
  732. Reference: https://wpvulndb.com/vulnerabilities/8967
  733. Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  734. Reference: https://github.com/WordPress/WordPress/commit/f1de7e42df29395c3314bf85bff3d1f4f90541de
  735. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17094
  736. [i] Fixed in: 4.3.14
  737.  
  738. [!] Title: WordPress 4.3.0-4.9 - HTML Language Attribute Escaping
  739. Reference: https://wpvulndb.com/vulnerabilities/8968
  740. Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  741. Reference: https://github.com/WordPress/WordPress/commit/3713ac5ebc90fb2011e98dfd691420f43da6c09a
  742. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17093
  743. [i] Fixed in: 4.3.14
  744.  
  745. [!] Title: WordPress 3.7-4.9 - 'newbloguser' Key Weak Hashing
  746. Reference: https://wpvulndb.com/vulnerabilities/8969
  747. Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  748. Reference: https://github.com/WordPress/WordPress/commit/eaf1cfdc1fe0bdffabd8d879c591b864d833326c
  749. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17091
  750. [i] Fixed in: 4.3.14
  751.  
  752. [+] WordPress theme in use: twentyfourteen - v1.5
  753.  
  754. [+] Name: twentyfourteen - v1.5
  755. | Last updated: 2017-11-16T00:00:00.000Z
  756. | Location: http://kamillotv.wex.pl/wp-content/themes/twentyfourteen/
  757. | Readme: http://kamillotv.wex.pl/wp-content/themes/twentyfourteen/readme.txt
  758. [!] The version is out of date, the latest version is 2.1
  759. | Style URL: http://kamillotv.wex.pl/wp-content/themes/twentyfourteen/style.css
  760. | Theme Name: Twenty Fourteen
  761. | Theme URI: https://wordpress.org/themes/twentyfourteen/
  762. | Description: In 2014, our default theme lets you create a responsive magazine website with a sleek, modern des...
  763. | Author: the WordPress team
  764. | Author URI: https://wordpress.org/
  765.  
  766. [+] Enumerating plugins from passive detection ...
  767. | 1 plugin found:
  768.  
  769. [+] Name: wordpress-seo - v2.3.5
  770. | Last updated: 2017-12-05T11:24:00.000Z
  771. | Location: http://kamillotv.wex.pl/wp-content/plugins/wordpress-seo/
  772. | Readme: http://kamillotv.wex.pl/wp-content/plugins/wordpress-seo/readme.txt
  773. | Changelog: http://kamillotv.wex.pl/wp-content/plugins/wordpress-seo/changelog.txt
  774. [!] The version is out of date, the latest version is 5.9.1
  775.  
  776. [!] Title: Yoast SEO <= 3.2.4 - Subscriber Settings Sensitive Data Exposure
  777. Reference: https://wpvulndb.com/vulnerabilities/8487
  778. Reference: https://www.wordfence.com/blog/2016/05/yoast-seo-vulnerability/
  779. [i] Fixed in: 3.2.5
  780.  
  781. [!] Title: Yoast SEO <= 3.2.5 - Unspecified Cross-Site Scripting (XSS)
  782. Reference: https://wpvulndb.com/vulnerabilities/8569
  783. Reference: https://wordpress.org/plugins/wordpress-seo/changelog/
  784. [i] Fixed in: 3.3.0
  785.  
  786. [!] Title: Yoast SEO <= 3.4.0 - Authenticated Stored Cross-Site Scripting (XSS)
  787. Reference: https://wpvulndb.com/vulnerabilities/8583
  788. Reference: https://plugins.trac.wordpress.org/changeset/1466243/wordpress-seo
  789. [i] Fixed in: 3.4.1
  790.  
  791. [!] Title: Yoast SEO <= 5.7.1 - Unauthenticated Cross-Site Scripting (XSS)
  792. Reference: https://wpvulndb.com/vulnerabilities/8960
  793. Reference: https://plugins.trac.wordpress.org/changeset/1766831/wordpress-seo/trunk/admin/google_search_console/class-gsc-table.php
  794. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16842
  795. [i] Fixed in: 5.8
  796.  
  797. [+] Enumerating usernames ...
  798. [+] Identified the following 1 user/s:
  799. +----+-------+---------------------------------+
  800. | Id | Login | Name |
  801. +----+-------+---------------------------------+
  802. | 1 | admin | admin, Autor w serwisie Kamillo |
  803. +----+-------+---------------------------------+
  804. [!] Default first WordPress username 'admin' is still used
  805.  
  806. [+] Finished: Sat Dec 16 23:56:31 2017
  807. [+] Requests Done: 93
  808. [+] Memory used: 36.223 MB
  809. [+] Elapsed time: 00:00:24
Advertisement
Add Comment
Please, Sign In to add comment