Описание
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2017-9066
- https://github.com/WordPress/WordPress/commit/76d77e927bb4d0f87c7262a50e28d84e01fd2b11
- https://codex.wordpress.org/Version_4.7.5
- https://twitter.com/skansing/status/865362551097393153
- https://wordpress.org/news/2017/05/wordpress-4-7-5
- https://wpvulndb.com/vulnerabilities/8815
- https://www.debian.org/security/2018/dsa-4090
- http://www.securityfocus.com/bid/98509
- http://www.securitytracker.com/id/1038520
Связанные уязвимости
CVSS3: 8.6
ubuntu
больше 8 лет назад
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
CVSS3: 8.6
nvd
больше 8 лет назад
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
CVSS3: 8.6
debian
больше 8 лет назад
In WordPress before 4.7.5, there is insufficient redirect validation i ...