Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-6389 PoC — WordPress 安全漏洞

Source
Associated Vulnerability
Title:WordPress 安全漏洞 (CVE-2018-6389)
Description:In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.
Description
Apache RewriteRule to mitigate potential DoS attack via Wordpress wp-admin/load-scripts.php file
Readme
# wordpress-fix-cve-2018-6389
Apache RewriteRule to mitigate potential DoS attack via Wordpress wp-admin/load-scripts.php file

Initial disclosure by Barak Tawily: https://baraktawily.blogspot.in/2018/02/how-to-dos-29-of-world-wide-websites.html
File Snapshot

[4.0K] /data/pocs/e8e1ccfdcf113947e57e4951c99043fd78a08b22 ├── [ 157] apache-rewrite ├── [1.0K] LICENSE └── [ 246] README.md 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →