[+] URL: https://blogs.unpas.ac.id/ [+] Started: Tue Apr 25 17:31:44 2017 [+] robots.txt available under: 'https://blogs.unpas.ac.id/robots.txt' [+] Interesting entry from robots.txt: https://blogs.unpas.ac.id/wp-admin/admin-ajax.php [!] The WordPress 'https://blogs.unpas.ac.id/readme.html' file exists exposing a version number [+] Interesting header: LINK: ; rel="https://api.w.org/", ; rel=shortlink [+] Interesting header: SERVER: Apache/2.4.6 [+] Interesting header: SET-COOKIE: wfvt_3759539884=58ff25a9346e1; expires=Tue, 25-Apr-2017 11:02:09 GMT; Max-Age=1800; path=/; httponly [+] Interesting header: X-POWERED-BY: PHP/5.6.30 [+] This site seems to be a multisite (http://codex.wordpress.org/Glossary#Multisite) [+] XML-RPC Interface available under: https://blogs.unpas.ac.id/xmlrpc.php [+] WordPress version 4.7.4 (Released on 2017-04-20) identified from meta generator, links opml [+] Enumerating installed plugins (only ones with known vulnerabilities) ... Time: 00:08:09 <========================================================================> (1493 / 1493) 100.00% Time: 00:08:09 [+] We found 5 plugins: [+] Name: akismet | Latest version: 3.3 | Last updated: 2017-02-23T17:23:00.000Z | Location: https://blogs.unpas.ac.id/wp-content/plugins/akismet/ [!] We could not determine a version so all vulnerabilities are printed out [!] Title: Akismet 2.5.0-3.1.4 - Unauthenticated Stored Cross-Site Scripting (XSS) Reference: https://wpvulndb.com/vulnerabilities/8215 Reference: http://blog.akismet.com/2015/10/13/akismet-3-1-5-wordpress/ Reference: https://blog.sucuri.net/2015/10/security-advisory-stored-xss-in-akismet-wordpress-plugin.html [i] Fixed in: 3.1.5 [+] Name: backupbuddy | Location: https://blogs.unpas.ac.id/wp-content/plugins/backupbuddy/ | Readme: https://blogs.unpas.ac.id/wp-content/plugins/backupbuddy/readme.txt [!] We could not determine a version so all vulnerabilities are printed out [!] Title: Backupbuddy - importbuddy.php Direct Request Remote Backup File Disclosure Reference: https://wpvulndb.com/vulnerabilities/6782 Reference: http://packetstormsecurity.com/files/120923/ Reference: http://seclists.org/fulldisclosure/2013/Mar/206 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2741 [i] Fixed in: 3.0 [!] Title: Backupbuddy - importbuddy.php step Parameter Manipulation Authentication Bypass Reference: https://wpvulndb.com/vulnerabilities/6783 Reference: http://packetstormsecurity.com/files/120923/ Reference: http://seclists.org/fulldisclosure/2013/Mar/206 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2743 [i] Fixed in: 3.0 [!] Title: Backupbuddy - importbuddy.php step Parameter Remote PHP Information Disclosure Reference: https://wpvulndb.com/vulnerabilities/6784 Reference: http://packetstormsecurity.com/files/120923/ Reference: http://seclists.org/fulldisclosure/2013/Mar/206 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2744 [i] Fixed in: 3.0 [!] Title: Backupbuddy - importbuddy.php Restore Operation Persistence Weakness Reference: https://wpvulndb.com/vulnerabilities/6785 Reference: http://packetstormsecurity.com/files/120923/ Reference: http://seclists.org/fulldisclosure/2013/Mar/206 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2742 [i] Fixed in: 3.0 [+] Name: groups | Latest version: 2.1.1 | Last updated: 2017-04-05T19:36:00.000Z | Location: https://blogs.unpas.ac.id/wp-content/plugins/groups/ [!] We could not determine a version so all vulnerabilities are printed out [!] Title: Groups 1.4.5 - Negated Role Capability H&ling Elevated Privilege Issue Reference: https://wpvulndb.com/vulnerabilities/7177 Reference: http://osvdb.org/show/osvdb/104940 [i] Fixed in: 1.4.6 [+] Name: portfolio | Latest version: 2.40 | Last updated: 2017-04-14T11:20:00.000Z | Location: https://blogs.unpas.ac.id/wp-content/plugins/portfolio/ [!] We could not determine a version so all vulnerabilities are printed out [!] Title: Multiple BestWebSoft Plugins - Authenticated Reflected GET Cross-Site Scripting (XSS) Reference: https://wpvulndb.com/vulnerabilities/8796 Reference: http://www.defensecode.com/advisories/DC-2017-02-014_50_WordPress_plugins_by_BestWebSoft_Advisory.pdf Reference: http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2017-April/010860.html [i] Fixed in: 2.40 [+] Name: searchterms-tagging-2 - v1.535 | Location: https://blogs.unpas.ac.id/wp-content/plugins/searchterms-tagging-2/ | Readme: https://blogs.unpas.ac.id/wp-content/plugins/searchterms-tagging-2/readme.txt [!] Title: SEO SearchTerms Tagging <= 2 1.535 - Authenticated SQL Injection Reference: https://wpvulndb.com/vulnerabilities/8248 Reference: http://cinu.pl/research/wp-plugins/mail_d14e213879cd60e80e538bde21c0359b.html Reference: http://blog.cinu.pl/2015/11/php-static-code-analysis-vs-top-1000-wordpress-plugins.html [+] Enumerating installed themes (only ones with known vulnerabilities) ... Time: 00:01:35 <==========================================================================> (279 / 279) 100.00% Time: 00:01:35 [+] We found 1 themes: [+] Name: slide | Location: https://blogs.unpas.ac.id/wp-content/themes/slide/ | Style URL: https://blogs.unpas.ac.id/wp-content/themes/slide/style.css [!] We could not determine a version so all vulnerabilities are printed out [!] Title: Slide - themify-ajax.php File Upload Arbitrary Code Execution Reference: https://wpvulndb.com/vulnerabilities/7493 Reference: http://packetstormsecurity.com/files/124097/ Reference: https://web.archive.org/web/http://1337day.com/exploit/22090 [+] Enumerating timthumb files ... Time: 00:15:35 <========================================================================> (2533 / 2533) 100.00% Time: 00:15:35 [+] We found 1 timthumb file/s: [+] https://blogs.unpas.ac.id/wp-content/themes/themorningafter/functions/thumb.php v2.8.11 [+] Enumerating usernames ... [+] We did not enumerate any usernames [+] Finished: Tue Apr 25 17:58:23 2017 [+] Requests Done: 4443 [+] Memory used: 162.422 MB [+] Elapsed time: 00:26:38