Get a Pentest and security assessment of your IT network.

News

The popular expert Nir Goldshlager has discovered an XMLRPC vulnerability which affects millions WordPress and Drupal websites exposing them to DoS Attack.

The XML vulnerability is present in WordPress and Drupal versions from 3.5 to 3.9.1. It basically exploits the use of entity expansion, this means that it replicates one large entity using a couple thousand characters repeatedly. The vulnerability is a problem related to the PHPs XML processor that was promptly fixed by Michael Adams and Andrew Nacin of the WordPress security team and David Rothstein of the Drupal security team. The PoC Exploit: (128MB Memory limit) is available at the address below”]

Source: https://securityaffairs.co/wordpress/27409/hacking/drupal-drupal-critical-flaw.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2