J
J
Jony13372016-05-09 13:17:40
Burglary protection
Jony1337, 2016-05-09 13:17:40

Old vulnerability (XML-RPC server accepts POST requests only)?

Hello everyone
. They gave the task of writing about the XML-RPC server accepts POST requests only vulnerability, which is on older versions of wordpress, I found a couple of articles in English about this bug, who knows what and what they think about this vulnerability, how to use it to put the site.
All questions are for informational purposes only!

Answer the question

In order to leave comments, you need to log in

1 answer(s)
L
latteo, 2016-05-09
@latteo

This is not a vulnerability, but an invalid data response.
Although it is used in some exploits to check that the requested url, with a high probability, belongs to a WP that has XML-RPC enabled. And if successful, an attack is launched, such as SQL Injection: https://www.exploit-db.com/exploits/3656//

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question