Page 2 of 8 results (0.009 seconds)

CVSS: 8.3EPSS: 0%CPEs: 1EXPL: 0

The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF. El plugin Canto versión 1.3.0, para WordPress permite un ataque SSRF en includes/lib/download.php?subdomain= The Canto plugin 2.1.1 for WordPress allows includes/lib/download.php?subdomain= SSRF. • https://gist.github.com/Hakooraevil/264cb21034f946eee62371e9111c36bb https://github.com/CantoDAM/Canto-Wordpress-Plugin https://wordpress.org/plugins/canto/#developers https://www.canto.com/integrations/wordpress • CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 8.3EPSS: 0%CPEs: 1EXPL: 1

The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/get.php?subdomain=SSRF. El plugin Canto versión 1.3.0 para WordPress, contiene una vulnerabilidad de tipo SSRF ciega. Permite a un atacante no autenticado poder realizar una petición a cualquier servidor interno y externo por medio de /includes/lib/get.php? • https://www.exploit-db.com/exploits/49189 http://packetstormsecurity.com/files/160358/WordPress-Canto-1.3.0-Server-Side-Request-Forgery.html https://gist.github.com/p4nk4jv/87aebd999ce4b28063943480e95fd9e0 https://github.com/CantoDAM/Canto-Wordpress-Plugin https://wordpress.org/plugins/canto/#developers https://www.canto.com/integrations/wordpress • CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 8.3EPSS: 0%CPEs: 1EXPL: 1

The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/tree.php?subdomain=SSRF. El plugin Canto versión 1.3.0 para WordPress, contiene una vulnerabilidad de tipo SSRF ciega. Permite a un atacante no autenticado poder realizar una petición a cualquier servidor interno y externo por medio de /includes/lib/tree.php? • https://www.exploit-db.com/exploits/49189 http://packetstormsecurity.com/files/160358/WordPress-Canto-1.3.0-Server-Side-Request-Forgery.html https://gist.github.com/p4nk4jv/87aebd999ce4b28063943480e95fd9e0 https://github.com/CantoDAM/Canto-Wordpress-Plugin https://wordpress.org/plugins/canto/#developers https://www.canto.com/integrations/wordpress • CWE-918: Server-Side Request Forgery (SSRF) •