Логотип exploitDog
bind:CVE-2024-1076
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-1076

Количество 2

Количество 2

nvd логотип

CVE-2024-1076

почти 2 года назад

The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8q5c-h63v-v869

почти 2 года назад

The SSL Zen WordPress plugin before 4.6.0 only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-1076

The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-8q5c-h63v-v869

The SSL Zen WordPress plugin before 4.6.0 only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.

CVSS3: 6.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу