6.1
CVSSv3

CVE-2017-9061

Published: 18/05/2017 Updated: 15/03/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 385
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

In WordPress prior to 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #862053 wordpress: CVE-2017-8295 Package: wordpress; Maintainer for wordpress is Craig Small <csmall@debianorg>; Source for wordpress is src:wordpress (PTS, buildd, popcon) Reported by: Markus Koschany <apo@debianorg> Date: Sun, 7 May 2017 19:57:02 UTC Severity: serious Tags: security, up ...
Debian Bug report logs - #862816 wordpress: Six security bugs in wordpress 474 and earlier Package: src:wordpress; Maintainer for src:wordpress is Craig Small <csmall@debianorg>; Reported by: Craig Small <csmall@debianorg> Date: Wed, 17 May 2017 11:57:06 UTC Severity: grave Tags: security, upstream Found in vers ...
Several vulnerabilities were discovered in wordpress, a web blogging tool They would allow remote attackers to force password resets, and perform various cross-site scripting and cross-site request forgery attacks For the stable distribution (jessie), these problems have been fixed in version 41+dfsg-1+deb8u14 For the upcoming stable (stretch) ...

Github Repositories

Week-7-8 Time taken to complete the lab and the assignment: 4 hrs Lab Demo: Title: WordPress 25-46 - Authenticated Stored Cross-Site Scripting via Image Filename Fixed in: 4210 procedure: When an image with a file name such as cengizhansahinsumofpwn<img src=a onerror=alert(documentcookie)>jpg is uploaded and viewed within WordPress the scri

Project 7 - WordPress Pentesting Time spent: 4 hours spent in total Objective: Find, analyze, recreate, and document three vulnerabilities affecting an old version of WordPress Pentesting Report (Required) File Too Large XSS Summary: The media upload section in Wordpress does not properly sanitize the name of the uploaded media, causing accesses to it to run arbitrary jav

Cybersecurity-Week-7-Project-WordPress-vs-Kali Project 7 - WordPress Pentesting Time spent: 45 hours spent in total Objective: Find, analyze, recreate, and document five vulnerabilities affecting an old version of WordPress Pentesting Report Authenticated Stored Cross-Site Scripting (XSS) ID: CVE-2015-5622 Summary: Vulnerability types: XSS Tested in version: 42 Fixed

example attacks on Wordpress

Cybersecurity-University-Week-7-Wordpress example attacks on Wordpress Project 7 - WordPress Pentesting Time spent: 10 hours spent in total Objective: Find, analyze, recreate, and document vulnerabilities affecting an old version of WordPress Pentesting Report WordPress 42 - Commenting XSS, CVE 2015-3440 Summary: This is a stored XSS attack affecting the comment system

Project 7 - WordPress Pentesting Objective: Find, analyze, recreate, and document five vulnerabilities affecting an old version of WordPress Pentesting Report WordPress 33-474 - Large File Upload Error XSS (CVE-ID: CVE-2017-9061) Summary: Vulnerability types: XSS Tested in version: 42 Fixed in version: 4215 GIF Walkthrough: user-imagesgithubuserconten

Project 7 - WordPress Pentesting Time spent: 4 hours spent in total Objective: Find, analyze, recreate, and document five vulnerabilities affecting an old version of WordPress Pentesting Report Authenticated Stored Cross-Site Scripting (XSS) in YouTube URL Embeds (CVE-2017-6817) Summary: Vulnerability types: XSS Tested in version: 42 Fixed in version: 4213 GIF Walk

Exploiting Wordpress vulnerabilities discovered via WPScan

WordPress Pentesting Time spent: 6 hours spent in total Objective: Find, analyze, recreate, and document five vulnerabilities affecting an old version of WordPress Setup VirtualBox - Virtual machine manager Kali Linux - Attack OS of choice WPDistillery - Creating a locally hosted Wordpress site WPScan - Vulnerability scanner Pentesting Report 1 CVE-2018-6390 - Denial O

For Codepath Security Course Assignment Week 7

Project 7 - WordPress Pentesting Time spent: 10 hours spent in total Objective: Find, analyze, recreate, and document five vulnerabilities affecting an old version of WordPress Pentesting Report 1 Authenticated Stored Cross-Site Scripting (XSS) in YouTube URL Embeds (CVE-2017-6817) Summary: Vulnerability types: XSS Tested in version: 42 Fixed in version: 473 GIF W

Project 7 - WordPress Pentesting Time spent: 12 hours spent in total Objective: Find, analyze, recreate, and document five vulnerabilities affecting an old version of WordPress Pentesting Report WordPress <= 42 - Unauthenticated Stored Cross-Site Scripting (XSS) Summary: Vulnerability types: XSS Tested in version: 42 Fixed in version: 421 Exploit Database 3684