Application error message
Unknown
Vulnerability Details
Attack details
HTTP Header input X-Forwarded-For was set to 12345'"\'\");|]*%00{%0d%0a<%00>%bf%27'???#
Error message found:
<b>Warning</b>: inet_pton() [<a href='function.inet-pton'>function.inet-pton</a>]: Unrecognized address 12345\'\"\\\'\\\");|]*%00{%0d%0a<%00>%bf%27\'#### in <b>/home/socialrecruitmentmonitor.com/www/wp-content/themes/MaxCommunique/functions.php</b> on line <b>185</b><br />
Request
GET /wp-login.php HTTP/1.1
Referer: http://www.google.com/search?hl=en&q=testing
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.94 Safari/537.36
Client-IP: 127.0.0.1
X-Forwarded-For: 12345'"\'\");|]*%00{%0d%0a<%00>%bf%27'####
X-Forwarded-Host: localhost
Accept-Language: en
Via: 1.1 wa.www.test.com
Origin: http://www.test.com/
Cookie: qtrans_cookie_test=qTranslate+Cookie+Test; PHPSESSID=7b368d6600e0413751e1483eb50288fb; wordpress_test_cookie=WP+Cookie+check
Host: login.socialrecruitmentmonitor.com
Connection: Keep-alive
Accept-Encoding: gzip,deflate
Accept: */*
Response
HTTP/1.1 200 OK
Server: Apache
Set-Cookie: qtrans_cookie_test=qTranslate+Cookie+Test; path=/; domain=login.socialrecruitmentmonitor.com
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Set-Cookie: wordpress_test_cookie=WP+Cookie+check; path=/
X-Frame-Options: SAMEORIGIN
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Content-Length: 2722
Accept-Ranges: bytes
Date: Sun, 03 Jul 2016 07:00:19 GMT
X-Varnish: 1812704148
Age: 0
Via: 1.1 varnish
Connection: keep-alive
Original-Content-Encoding: gzip
Actions
View on HackerOneReport Stats
- Report ID: 148963
- State: Closed
- Substate: resolved
- Upvotes: 3