b3gund4L icon

Kuninganizer

b3gund4L | PRO | 04/25/17 09:13:35 AM UTC | 0 ⭐ | 38905 👁️ | Never ⏰ | []
Bash |

3.12 KB

|

None

|

0 👍

/

0 👎

[i] It seems like you have not updated the database for some time.
[?] Do you want to update now? [Y]es [N]o [A]bort, default: [N]y
[i] Updating the Database ...
[i] Update completed.
[+] URL: http://kuninganizer.com/
[+] Started: Tue Apr 25 10:30:04 2017
 
[+] robots.txt available under: 'http://kuninganizer.com/robots.txt'
[+] Interesting entry from robots.txt: http://kuninganizer.com/wp-admin/admin-ajax.php
[!] The WordPress 'http://kuninganizer.com/readme.html' file exists exposing a version number
[+] Interesting header: AGE: 63
[+] Interesting header: SERVER: Rocket Booster
[+] Interesting header: X-CACHE: HIT
[+] Interesting header: X-CACHE-HITS: 2
[+] Interesting header: X-POWERED-BY: Warna Web Accelerator
[+] Interesting header: X-VARNISH: 7379904 8230809
[+] XML-RPC Interface available under: http://kuninganizer.com/xmlrpc.php
 
[+] WordPress version 4.7.4 (Released on 2017-04-20) identified from meta generator, links opml
 
[+] WordPress theme in use: Newspaper - v7.8
 
[+] Name: Newspaper - v7.8
 |  Location: http://kuninganizer.com/wp-content/themes/Newspaper/
 |  Readme: http://kuninganizer.com/wp-content/themes/Newspaper/readme.txt
 |  Style URL: http://kuninganizer.com/wp-content/themes/Newspaper/style.css
 |  Theme Name: Newspaper
 |  Theme URI: http://tagdiv.com
 |  Description: Premium wordpress template, clean and easy to use.
 |  Author: tagDiv
 |  Author URI: http://themeforest.net/user/tagDiv/portfolio
 
[+] Enumerating plugins from passive detection ...
 | 3 plugins found:
 
[+] Name: google-captcha - v1.27
 |  Last updated: 2017-04-14T13:02:00.000Z
 |  Location: http://kuninganizer.com/wp-content/plugins/google-captcha/
 |  Readme: http://kuninganizer.com/wp-content/plugins/google-captcha/readme.txt
[!] The version is out of date, the latest version is 1.28
 
[!] Title: Multiple BestWebSoft Plugins - Authenticated Reflected GET Cross-Site Scripting (XSS)
    Reference: https://wpvulndb.com/vulnerabilities/8796
    Reference: http://www.defensecode.com/advisories/DC-2017-02-014_50_WordPress_plugins_by_BestWebSoft_Advisory.pdf
    Reference: http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2017-April/010860.html
[i] Fixed in: 1.28
 
[+] Name: js_composer
 |  Location: http://kuninganizer.com/wp-content/plugins/js_composer/
 
[!] We could not determine a version so all vulnerabilities are printed out
 
[!] Title: Visual Composer <= 4.7.3 - Multiple Unspecified Cross-Site Scripting (XSS)
    Reference: https://wpvulndb.com/vulnerabilities/8208
    Reference: http://codecanyon.net/item/visual-composer-page-builder-for-wordpress/242431
    Reference: https://forums.envato.com/t/visual-composer-security-vulnerability-fix/10494/7
[i] Fixed in: 4.7.4
 
[+] Name: wordpress-seo - v4.5
 |  Last updated: 2017-04-11T09:39:00.000Z
 |  Location: http://kuninganizer.com/wp-content/plugins/wordpress-seo/
 |  Readme: http://kuninganizer.com/wp-content/plugins/wordpress-seo/readme.txt
[!] The version is out of date, the latest version is 4.6
 
[+] Finished: Tue Apr 25 10:42:53 2017
[+] Requests Done: 104
[+] Memory used: 66.355 MB
[+] Elapsed time: 00:12:49

Comments