Vulnerabilities
preg_match() only check if $_GET['code'] contains at least one letter or digit (missing ^ and $ inside regexp).
1 MIN READ
Vulnerabilities
preg_match() only check if $_GET['code'] contains at least one letter or digit (missing ^ and $ inside regexp).
1 MIN READ
Vulnerabilities
Administrator privileges are NOT checked when we pass $_GET['wprss-bulk'].
1 MIN READ
Vulnerabilities
Slashes are removed from $_GET['condition'].
1 MIN READ
Vulnerabilities
$_GET['error_message'] is not escaped.
1 MIN READ
Vulnerabilities
Anyone can access pulse/admin/inc/gal-sort.php.
1 MIN READ
Vulnerabilities
By default .swf files in Media Manager are allowed.
1 MIN READ
Vulnerabilities
Regular user (created using wp-login.php?action=register) can run backup functionality.
1 MIN READ
Vulnerabilities
Link to created backup file is saved in public log.
1 MIN READ
From 0 to pentesting hero
How to convince the user to delete his account on the website without his consent?
17-04-2019
3 MIN READ