Startseite ▼ Bookkeeping
Online ▼ Sicherheits
Überprüfungs ▼
Verwaltetes
DNS ▼
Info
Bestellen/Erneuern
FAQ
AUP
Dynamic DNS Clients
Domaine konfigurieren Dyanmic DNS Update Password Netzwerk
Überwachung ▼
Enterprise
Erweiterte
Standard
Gratis Test
FAQ
Preis/Funktionszusammenfassung
Bestellen
Beispiele
Konfigurieren/Status Alarm Profile | |||
Test Kennung: | 1.3.6.1.4.1.25623.1.0.812692 |
Kategorie: | Web application abuses |
Titel: | WordPress 'load-scripts.php' DoS Vulnerability - Windows |
Zusammenfassung: | WordPress is prone to a denial of service (DoS); vulnerability. |
Beschreibung: | Summary: WordPress is prone to a denial of service (DoS) vulnerability. Vulnerability Insight: The flaw exists as the file 'load-scripts.php' do not require any authentication and file selectively calls required JavaScript files by passing their names into the 'load' parameter, separated by a comma. Vulnerability Impact: Successful exploitation will allow remote attackers to conduct a denial of service condition on affected system. Affected Software/OS: WordPress versions 4.9.2 and prior. Solution: No known solution was made available for at least one year since the disclosure of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade to a newer release, disable respective features, remove the product or replace the product by another one. CVSS Score: 5.0 CVSS Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P |
Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2018-6389 BugTraq ID: 103060 http://www.securityfocus.com/bid/103060 https://www.exploit-db.com/exploits/43968/ https://baraktawily.blogspot.fr/2018/02/how-to-dos-29-of-world-wide-websites.html https://github.com/UltimateHackers/Shiva https://github.com/WazeHell/CVE-2018-6389 https://thehackernews.com/2018/02/wordpress-dos-exploit.html https://wpvulndb.com/vulnerabilities/9021 http://www.securitytracker.com/id/1040347 |
Copyright | Copyright (C) 2018 Greenbone Networks GmbH |
Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |