‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. zelphirkalt · · focus · HN ↗
    These are the reason, why every easily reachable web server will be spammed with /something/something.php?somearg=someval. If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates. Maybe right after MS Teams or Sharepoint or some stuff like that.
    1. toyg · · focus · HN ↗
      TBF, some of it is structural: if you're the most popular anything on the internet, you'll be the most attacked and the most exploited, and hence the most exploitable.
      1. Retr0id · · focus · HN ↗
        That's not really true.

        Edit: wow that's a lot of downvotes! I'm surprised people can't identify a trivial reasoning failure.

        1. dwattttt · · focus · HN ↗
          You could've included a little more nuance. An interpretation of your response is "being the most popular remotely accessible software" != "the most attacked", which would need defending.
          1. hdgvhicv · · focus · HN ↗
            25 years ago alache hosted about 10 times as many sites as IIS, yet IIS was always the one being backed.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.