Đang mở báo cáo bảo mật của www.coxlab.berkeley.edu
www.coxlab.berkeley.edu
Đang tải báo cáo bảo mật của www.coxlab.berkeley.edu
www.coxlab.berkeley.edu
www.coxlab.berkeley.edu có an toàn không? Điểm bảo mật 78,3/100 | CyStack
www.coxlab.berkeley.edu
COX LAB | UC Berkeley
UC Berkeley pushes the boundaries of knowledge, challenges convention and expands opportunity to create the leaders of tomorrow.
Lĩnh vực
Khoa học và Giáo dục / Đại học và Cao đẳng
Nguồn gốc
Hoa Kỳ
Xếp hạng toàn cầu
#3.455
Xếp hạng tại Hoa Kỳ
#846
Cập nhật lúc
C78,3/100
Mức an toàn
Khá
Độ tin cậy dữ liệu
Cao
Phạm vi đã kiểm tra
94,1%
Điểm càng cao, hệ thống càng ghi nhận được nhiều biện pháp bảo vệ quan sát từ bên ngoài. Trang này không nhằm chứng nhận website uy tín, hợp pháp hay hoàn toàn không có lỗ hổng.
Trang web “www.coxlab.berkeley.edu” có an toàn không?
Tính đến 00:12 ngày 9/9/2026, www.coxlab.berkeley.edu đạt 78,3/100 điểm an toàn (đạt hạng C: “Khá”). Hệ thống quét tự động của CyStack ghi nhận 12 vấn đề cần xem xét sau khi kiểm tra 94,1% hạng mục. Chủ sở hữu website nên ưu tiên khắc phục “Nguồn nội dung được phép tải (CSP)”, sau đó rà soát các mục còn lại theo mức độ ảnh hưởng.
Có dấu hiệu lừa đảo, phishing hoặc mã độc nào liên quan đến www.coxlab.berkeley.edu không?
CyStack chưa ghi nhận www.coxlab.berkeley.edu hay hạ tầng liên quan trong bất kỳ danh sách cảnh báo lừa đảo, phishing hoặc mã độc nào tại thời điểm quét, sau khi đối chiếu 5 nguồn danh tiếng trực tuyến. Kết quả này phản ánh quan sát từ bên ngoài, không đảm bảo website an toàn tuyệt đối và không xác nhận tư cách pháp lý hay uy tín của tổ chức.
Điều gì đang ảnh hưởng đến độ an toàn của www.coxlab.berkeley.edu?
Chứng thư SSL hợp lệ vẫn chưa đủ để khẳng định www.coxlab.berkeley.edu là website an toàn, uy tín hay không có dấu hiệu lừa đảo. Để đánh giá toàn diện hơn, báo cáo còn kiểm tra phishing và mã độc, email lộ lọt, IP và cổng mở, tên miền phụ, công nghệ cùng các CVE có thể liên quan đến phiên bản ghi nhận được.
www.coxlab.berkeley.edu có dùng HTTPS và chứng thư SSL còn hợp lệ không?
www.coxlab.berkeley.edu đang dùng chứng thư SSL hợp lệ tại thời điểm đánh giá, có hiệu lực đến ngày 26 tháng 11, 2026. Trạng thái này có thể thay đổi khi chứng thư hết hạn hoặc máy chủ đổi cấu hình.
Dữ liệu được tổng hợp từ các hệ thống giám sát an ninh mạng của CyStack
CyStack tổng hợp kết quả quét từ các hệ thống giám sát an ninh mạng nội bộ, bao gồm CyStack VulnScan và CyStack Threat Intelligence, cùng các nguồn dữ liệu công khai trên Internet. Quá trình đánh giá chỉ quan sát và phân tích thông tin sẵn có, không đăng nhập trái phép, thử mật khẩu, gửi mã khai thác hay làm thay đổi, gián đoạn hệ thống được đánh giá.
Có 3 tiêu chí không đạt hoặc cảnh báo có ảnh hưởng lớn nhất tới kết quả của www.coxlab.berkeley.edu.
Nguồn nội dung được phép tải (CSP)Phản hồi HTML trang gốc được kiểm tra không có header Content-Security-Policy.Cao
Vì sao cần quan tâm
Content Security Policy (CSP) giới hạn nguồn được phép cung cấp script, style, frame và nội dung khác cho trình duyệt. Chính sách chặt chẽ giúp giảm tác động nếu kẻ tấn công chèn được nội dung vào trang.
Nên làm gì
Chỉ khai báo các nguồn ứng dụng thực sự cần, kiểm thử chính sách trước khi kích hoạt và hạn chế quy tắc ký tự đại diện (*) quá rộng, unsafe-inline cùng unsafe-eval.
Phạm vi của tiêu chí
Tiêu chí này chỉ đánh giá phản hồi và nội dung của trang chủ mà hệ thống truy cập được; các trang hoặc luồng đăng nhập khác có thể có cấu hình khác.
Các CVE có thể liên quan đến phiên bản phát hiện đượcTìm thấy 69 ứng viên CVE có khả năng áp dụng, trong đó 25 ứng viên mức high hoặc critical.Cao
Vì sao cần quan tâm
Kiểm tra này chỉ đối chiếu sản phẩm quan sát được khi có phiên bản đáng tin cậy và định danh CPE chính xác, sử dụng dữ liệu áp dụng từ National Vulnerability Database (NVD). Mọi kết quả khớp chỉ là đầu mối, chưa phải lỗ hổng đã xác nhận vì phần mềm cài đặt có thể đã chứa bản vá hoặc khác với phiên bản hiển thị ra Internet.
Nên làm gì
Chống nhúng trang lừa đảo (clickjacking)Phản hồi HTML trang gốc được kiểm tra không có giới hạn CSP frame-ancestors hoặc X-Frame-Options có hiệu lực.Trung bình
Vì sao cần quan tâm
Website khác có thể nhúng trang này vào một frame bị che hoặc gây hiểu nhầm để lừa người dùng bấm vào hành động ngoài ý muốn. Quy tắc frame cho trình duyệt biết website nào được phép nhúng trang.
Nên làm gì
Thiết lập frame-ancestors trong CSP chỉ cho các website tin cậy cần thiết và giữ X-Frame-Options cho trình duyệt cũ khi phù hợp.
–
Hệ điều hành
Hạ tầng công khai và phần mềm có thể quan sát
Mỗi địa chỉ IP công khai được nhóm cùng dịch vụ đang mở, sản phẩm đã nhận diện và các CVE có khả năng liên quan đến phiên bản quan sát được.
Đã hoàn tất kiểm thử 58 cổng TCP
23.185.0.3
2 dịch vụ đang mở22 sản phẩm đã nhận diện
Nhà cung cấp hạ tầng hoặc mạngChưa xác định được nhà cung cấp
Vị trí mạng–
ASN–
80HTTPWordPressBootstrapFastly+1869 CVE có thể liên quan
2620:12a:8000::3
0 dịch vụ đang mở
Nhà cung cấp hạ tầng hoặc mạngChưa xác định được nhà cung cấp
Vị trí mạng–
ASN–
Không quan sát thấy dịch vụ đang mở trên địa chỉ này trong các cổng đã kiểm tra.
2620:12a:8001::3
0 dịch vụ đang mở
Nhà cung cấp hạ tầng hoặc mạngChưa xác định được nhà cung cấp
Vị trí mạng–
ASN–
Không quan sát thấy dịch vụ đang mở trên địa chỉ này trong các cổng đã kiểm tra.
Email @berkeley.edu có xuất hiện trong dữ liệu lộ lọt hoặc nhật ký của phần mềm đánh cắp thông tin (infostealer) không?
Hiện ghi nhận 1.743 bản ghi email lộ lọt khớp tên miền berkeley.edu. Các bản ghi này có thể đã cũ hoặc đã được xử lý. Chủ sở hữu website nên xác minh trước khi đổi mật khẩu hoặc khóa các tài khoản liên quan.
www.coxlab.berkeley.edu đang công khai những IP, dịch vụ và cổng nào?
Ghi nhận được 3 IP công khai và 2 cổng đang mở của www.coxlab.berkeley.edu. Cổng mở không tương đương với việc có lỗ hổng, nhưng chủ sở hữu website nên cập nhật thường xuyên và giới hạn truy cập cho từng dịch vụ công khai.
Đã phát hiện được bao nhiêu tên miền phụ của berkeley.edu?
Ghi nhận 1.105+ tên miền phụ công khai của berkeley.edu. Danh sách này giúp nhận biết thêm các cổng vào như API, hệ thống quản trị hay môi trường thử nghiệm, nhưng không có nghĩa tên miền phụ nào cũng có rủi ro.
Xác nhận chính xác gói phần mềm đang cài và đọc cảnh báo của nhà cung cấp. Nếu bản cài đặt thực sự bị ảnh hưởng, hãy áp dụng bản vá hoặc nâng cấp lên phiên bản đã sửa lỗi.
Bằng chứng và phạm vi kiểm tra
Nguồn dữ liệu:
nvd
Liên kết nguồn:
https://nvd.nist.gov/
Sản phẩm phần mềm phát hiện:
3
Sản phẩm đủ dữ liệu để đối chiếu:
1
Sản phẩm đã đối chiếu:
1
Sản phẩm chưa thể đối chiếu:
2
Lỗ hổng có khả năng liên quan:
69
Tổng số lỗ hổng có khả năng liên quan:
69
Số lỗ hổng có khả năng liên quan đang hiển thị:
25
Mã CVE có khả năng liên quan:
CVE-2018-1000773, CVE-2018-19296, CVE-2018-20148, CVE-2018-20151, CVE-2019-17669, CVE-2019-17670, CVE-2019-17673, CVE-2019-17675, CVE-2019-20041, CVE-2019-8942… và 15 giá trị khác
Không hiển thị 16 trường bằng chứng bổ sung tại đây.
WordPress4.9.8Blogs · CMS4.9.869 CVE có thể liên quanCVSS 9,8
Định danh CPEcpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*, cpe:2.3:a:wordpress:wordpress:4.9.8:*:*:*:*:*:*:*
Độ tin cậyTrung bình
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.
Hệ thống tìm thấy 69 kết quả tiềm năng cho sản phẩm này, nhưng báo cáo chỉ lưu một phần chi tiết đại diện.
BootstrapChưa thấy phiên bảnUI FrameworksChưa thấy phiên bản
Định danh CPEcpe:2.3:a:getbootstrap:bootstrap:*:*:*:*:*:*:*:*
Độ tin cậyTrung bình
Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
jQueryChưa thấy phiên bảnJavaScript LibrariesChưa thấy phiên bản
Định danh CPEcpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:*
Độ tin cậyTrung bình
jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
Query Migrate is a javascript library that allows you to preserve the compatibility of your jQuery code developed for versions of jQuery older than 1.9.
Định danh CPEcpe:2.3:a:wp_gcalendar:wp_gcalendar:1.2.0:*:*:*:*:wordpress:*:*
Độ tin cậyTrung bình
443HTTPSĐã xác minh TLSWordPressBootstrapFastly+1969 CVE có thể liên quan
Sản phẩmPhiên bảnLỗ hổng có thể liên quan
WordPress4.9.8Blogs · CMS4.9.869 CVE có thể liên quanCVSS 9,8
Định danh CPEcpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*, cpe:2.3:a:wordpress:wordpress:4.9.8:*:*:*:*:*:*:*
Độ tin cậyTrung bình
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution due to an incomplete fix for CVE-2017-1000600. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed incorrectly, leading to XSS. The XSS results in administrative access, which allows arbitrary changes to .php files. This is related to wp-admin/includes/ajax-actions.php and wp-includes/comment.php.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 4.1.34. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an administrative user on the Plugins -> Add New -> Upload Plugin screen in WordPress. If FTP credentials are requested for installation (in order to move the file into place outside of the `uploads` directory) then the uploaded file remains temporary available in the Media Library despite it not being allowed. If the `DISALLOW_FILE_EDIT` constant is set to `true` on the site _and_ FTP credentials are required when uploading a new theme or plugin, then this technically allows an RCE when the user would otherwise have no means of executing arbitrary PHP code. This issue _only_ affects Administrator level users on single site installations, and Super Admin level users on Multisite installations where it's otherwise expected that the user does not have permission to upload or execute arbitrary PHP code. Lower level users are not affected. Sites where the `DISALLOW_FILE_MODS` constant is set to `true` are not affected. Sites where an administrative user either does not need to enter FTP credentials or they have access to the valid FTP credentials, are not affected. The issue was fixed in WordPress 6.4.3 on January 30, 2024 and backported to versions 6.3.3, 6.2.4, 6.1.5, 6.0.7, 5.9.9, 5.8.9, 5.7.11, 5.6.13, 5.5.14, 5.4.15, 5.3.17, 5.2.20, 5.1.18, 5.0.21, 4.9.25, 2.8.24, 4.7.28, 4.6.28, 4.5.31, 4.4.32, 4.3.33, 4.2.37, and 4.1.40. A workaround is available. If the `DISALLOW_FILE_MODS` constant is defined as `true` then it will not be possible for any user to upload a plugin and therefore this issue will not be exploitable.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this vulnerability.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution due to an incomplete fix for CVE-2017-1000600. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed incorrectly, leading to XSS. The XSS results in administrative access, which allows arbitrary changes to .php files. This is related to wp-admin/includes/ajax-actions.php and wp-includes/comment.php.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 4.1.34. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an administrative user on the Plugins -> Add New -> Upload Plugin screen in WordPress. If FTP credentials are requested for installation (in order to move the file into place outside of the `uploads` directory) then the uploaded file remains temporary available in the Media Library despite it not being allowed. If the `DISALLOW_FILE_EDIT` constant is set to `true` on the site _and_ FTP credentials are required when uploading a new theme or plugin, then this technically allows an RCE when the user would otherwise have no means of executing arbitrary PHP code. This issue _only_ affects Administrator level users on single site installations, and Super Admin level users on Multisite installations where it's otherwise expected that the user does not have permission to upload or execute arbitrary PHP code. Lower level users are not affected. Sites where the `DISALLOW_FILE_MODS` constant is set to `true` are not affected. Sites where an administrative user either does not need to enter FTP credentials or they have access to the valid FTP credentials, are not affected. The issue was fixed in WordPress 6.4.3 on January 30, 2024 and backported to versions 6.3.3, 6.2.4, 6.1.5, 6.0.7, 5.9.9, 5.8.9, 5.7.11, 5.6.13, 5.5.14, 5.4.15, 5.3.17, 5.2.20, 5.1.18, 5.0.21, 4.9.25, 2.8.24, 4.7.28, 4.6.28, 4.5.31, 4.4.32, 4.3.33, 4.2.37, and 4.1.40. A workaround is available. If the `DISALLOW_FILE_MODS` constant is defined as `true` then it will not be possible for any user to upload a plugin and therefore this issue will not be exploitable.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the password that was generated by default.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this vulnerability.
Sản phẩm đối chiếu: WordPress 4.9.8 Độ tin cậy: Trung bình
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.
Hệ thống tìm thấy 69 kết quả tiềm năng cho sản phẩm này, nhưng báo cáo chỉ lưu một phần chi tiết đại diện.
BootstrapChưa thấy phiên bảnUI FrameworksChưa thấy phiên bản
Định danh CPEcpe:2.3:a:getbootstrap:bootstrap:*:*:*:*:*:*:*:*
Độ tin cậyTrung bình
Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
jQueryChưa thấy phiên bảnJavaScript LibrariesChưa thấy phiên bản
Định danh CPEcpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:*
Độ tin cậyTrung bình
jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
Query Migrate is a javascript library that allows you to preserve the compatibility of your jQuery code developed for versions of jQuery older than 1.9.