Описание
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2017-9066
- https://github.com/WordPress/WordPress/commit/76d77e927bb4d0f87c7262a50e28d84e01fd2b11
- https://codex.wordpress.org/Version_4.7.5
- https://twitter.com/skansing/status/865362551097393153
- https://wordpress.org/news/2017/05/wordpress-4-7-5
- https://wpvulndb.com/vulnerabilities/8815
- https://www.debian.org/security/2018/dsa-4090
- http://www.securityfocus.com/bid/98509
- http://www.securitytracker.com/id/1038520
Связанные уязвимости
CVSS3: 8.6
ubuntu
около 8 лет назад
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
CVSS3: 8.6
nvd
около 8 лет назад
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
CVSS3: 8.6
debian
около 8 лет назад
In WordPress before 4.7.5, there is insufficient redirect validation i ...