Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.900968
Kategorie:Denial of Service
Titel:WordPress wp-trackback.php Denial of Service Vulnerability
Zusammenfassung:The host is running WordPress and is prone to Denial of Service; vulnerability.
Beschreibung:Summary:
The host is running WordPress and is prone to Denial of Service
vulnerability.

Vulnerability Insight:
An error occurs in wp-trackbacks.php due to improper validation of user
supplied data passed into 'mb_convert_encoding()' function. This can be
exploited by sending multiple-source character encodings into the function.

Vulnerability Impact:
Successful exploitation will allow attacker to cause a Denial of Service
due to high CPU consumption.

Affected Software/OS:
WordPress version prior to 2.8.5 on all platforms.

Solution:
Upgrade to WordPress version 2.8.5 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-3622
http://seclists.org/fulldisclosure/2009/Oct/263
http://codes.zerial.org/php/wp-trackbacks_dos.phps
http://rooibo.wordpress.com/2009/10/17/agujero-de-seguridad-en-wordpress/
http://security-sh3ll.blogspot.com/2009/10/wordpress-resource-exhaustion-denial-of.html
http://marc.info/?l=oss-security&m=125612393329041&w=2
http://marc.info/?l=oss-security&m=125614592004825&w=2
http://www.osvdb.org/59077
http://securitytracker.com/id?1023072
http://secunia.com/advisories/37088
http://www.vupen.com/english/advisories/2009/2986
XForce ISS Database: wordpress-wptrackback-dos(53884)
https://exchange.xforce.ibmcloud.com/vulnerabilities/53884
CopyrightCopyright (C) 2009 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.