CVE-2016-4029 (wordpress)

CVE-2016-4029 (wordpress)

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

Source: CVE-2016-4029 (wordpress)

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다