Application error message

Disclosed: 2017-03-31 02:17:52 By linkks To radancy
Unknown
Vulnerability Details
Attack details HTTP Header input X-Forwarded-For was set to 12345'"\'\");|]*%00{%0d%0a<%00>%bf%27'???# Error message found: <b>Warning</b>: inet_pton() [<a href='function.inet-pton'>function.inet-pton</a>]: Unrecognized address 12345\'\&quot;\\\'\\\&quot;);|]*%00{%0d%0a&lt;%00&gt;%bf%27\'#### in <b>/home/socialrecruitmentmonitor.com/www/wp-content/themes/MaxCommunique/functions.php</b> on line <b>185</b><br /> Request GET /wp-login.php HTTP/1.1 Referer: http://www.google.com/search?hl=en&q=testing User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.94 Safari/537.36 Client-IP: 127.0.0.1 X-Forwarded-For: 12345'"\'\");|]*%00{%0d%0a<%00>%bf%27'#### X-Forwarded-Host: localhost Accept-Language: en Via: 1.1 wa.www.test.com Origin: http://www.test.com/ Cookie: qtrans_cookie_test=qTranslate+Cookie+Test; PHPSESSID=7b368d6600e0413751e1483eb50288fb; wordpress_test_cookie=WP+Cookie+check Host: login.socialrecruitmentmonitor.com Connection: Keep-alive Accept-Encoding: gzip,deflate Accept: */* Response HTTP/1.1 200 OK Server: Apache Set-Cookie: qtrans_cookie_test=qTranslate+Cookie+Test; path=/; domain=login.socialrecruitmentmonitor.com Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Set-Cookie: wordpress_test_cookie=WP+Cookie+check; path=/ X-Frame-Options: SAMEORIGIN Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 2722 Accept-Ranges: bytes Date: Sun, 03 Jul 2016 07:00:19 GMT X-Varnish: 1812704148 Age: 0 Via: 1.1 varnish Connection: keep-alive Original-Content-Encoding: gzip
Actions
View on HackerOne
Report Stats
  • Report ID: 148963
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report