wpscanteam / wpscan

WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via contact@wpscan.com
https://wpscan.com/wordpress-cli-scanner
Other
8.59k stars 1.26k forks source link

WP 3.6.1 - Secu fixes #280

Closed erwanlr closed 11 years ago

erwanlr commented 11 years ago

http://wordpress.org/news/2013/09/wordpress-3-6-1/

More info about the 3 secu vulns ? :p

Edit: Found the first one details: http://vagosec.org/2013/09/wordpress-php-object-injection/

fgeek commented 11 years ago

CVEs assigned http://www.openwall.com/lists/oss-security/2013/09/12/1

firefart commented 11 years ago

https://github.com/WordPress/WordPress/compare/3.6...3.6.1

erwanlr commented 11 years ago

Reminder for the fingerprinting:

Unique file(s) for v3.6.1 :
03eaffeef39119f0523a49c7f9767f3b  ./3.6.1/wp-admin/js/common.js
b45d244b6669aef59434fc30265f01f9  ./3.6.1/wp-admin/js/common.min.js
92c9ccfa9216499d48ecc11e6d9887d5  ./3.6.1/wp-includes/js/jquery/jquery.js
a3d703f0f3b6c2171edea4410ec478b5  ./3.6.1/wp-includes/js/tinymce/plugins/wordpress/editor_plugin.js
a7d139d6d9506e005e7aee90d5c7918b  ./3.6.1/wp-includes/js/tinymce/plugins/wordpress/editor_plugin_src.js
ethicalhack3r commented 11 years ago

Currently away from home so cant help look until the weekend. I wonder if it has anything to do with bugcrowds vuln assessment? Info on their blog. On 12 Sep 2013 14:59, "erwanlr" notifications@github.com wrote:

Reminder for the fingerprinting:

Unique file(s) for v3.6.1 : 03eaffeef39119f0523a49c7f9767f3b ./3.6.1/wp-admin/js/common.js b45d244b6669aef59434fc30265f01f9 ./3.6.1/wp-admin/js/common.min.js 92c9ccfa9216499d48ecc11e6d9887d5 ./3.6.1/wp-includes/js/jquery/jquery.js a3d703f0f3b6c2171edea4410ec478b5 ./3.6.1/wp-includes/js/tinymce/plugins/wordpress/editor_plugin.js a7d139d6d9506e005e7aee90d5c7918b ./3.6.1/wp-includes/js/tinymce/plugins/wordpress/editor_plugin_src.js

— Reply to this email directly or view it on GitHubhttps://github.com/wpscanteam/wpscan/issues/280#issuecomment-24316380 .

erwanlr commented 11 years ago

Added to the db yesterday, closing