【问题标题】:Understanding WPScan results and how to fix vulnerabilities了解 WPScan 结果以及如何修复漏洞
【发布时间】:2018-11-01 02:27:23
【问题描述】:

我有这个漏洞

[!] Title: sitepress-multilingual-cms - Full Path Disclosure
    Reference: https://wpvulndb.com/vulnerabilities/6104
[i] Fixed in: 3.1.7.2

,

[!] Title: WPML <= 3.1.7.2 - Multiple Vulnerabilities (Including SQLi)
    Reference: https://wpvulndb.com/vulnerabilities/7843
    Reference: http://seclists.org/bugtraq/2015/Mar/60
    Reference: http://wpml.org/2015/03/wpml-security-update-bug-and-fix/
    Reference: http://packetstormsecurity.com/files/130810/
    Reference: http://klikki.fi/adv/wpml.html
    Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2314
    Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2791
    Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2792
    Reference: https://www.exploit-db.com/exploits/36414/
[i] Fixed in: 3.1.9

    [!] Title: WPML 2.9.3-3.2.6 - Cross-Site Scripting (XSS) in Accept-Language Header
    Reference: https://wpvulndb.com/vulnerabilities/8173
    Reference: http://blog.secupress.fr/en/xss-wpml-header-405.html
[i] Fixed in: 3.2.7

根据报告,他们都应该从 3.2.7 版本修复,但我有 3.9.4 版本并且仍然得到该结果

这是我当前的版本:

那么我应该如何摆脱它们呢?

【问题讨论】:

  • 您应该咨询 WPML 支持,而不是社区。或者更好的是,如果支持没有帮助,请切换产品。
  • 不熟悉此扫描仪。猜测它读取磁盘上的文件。您是否在磁盘上可能正在读取的旧版本有旧版本?或者,您是否可能正在运行易受攻击的版本并且不知道它?

标签: wordpress security


【解决方案1】:

瑞恩在这里。 WPScan 开发人员之一。

看起来 WPScan 无法检测到已安装的插件版本。发生这种情况时,WPScan 将显示警告,然后输出该插件的所有已知漏洞。这是为了让用户自己进行调查,而不是可能导致假阴性结果。

如果您回顾 WPScan 输出,您应该会看到一条警告:

我们无法确定版本,因此打印了所有漏洞 出去

【讨论】:

    猜你喜欢
    • 2019-02-23
    • 2021-08-14
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2022-01-17
    • 2021-08-20
    • 1970-01-01
    • 2020-02-15
    相关资源
    最近更新 更多