Adds a line about GHOST when XMLRPC is enabled, Fixes #763
This commit is contained in:
@@ -188,6 +188,7 @@ def main
|
|||||||
|
|
||||||
if wp_target.has_xml_rpc?
|
if wp_target.has_xml_rpc?
|
||||||
puts "#{info('[+]')} XML-RPC Interface available under: #{wp_target.xml_rpc_url}"
|
puts "#{info('[+]')} XML-RPC Interface available under: #{wp_target.xml_rpc_url}"
|
||||||
|
puts "#{warning('[!]')} This may allow the GHOST vulnerability to be exploited, please see http://blog.spiderlabs.com/2015/01/ghost-gethostbyname-heap-overflow-in-glibc-cve-2015-0235.html for a PoC"
|
||||||
end
|
end
|
||||||
|
|
||||||
if wp_target.upload_directory_listing_enabled?
|
if wp_target.upload_directory_listing_enabled?
|
||||||
|
|||||||
Reference in New Issue
Block a user