BruteForce in to Admin Account

Disclosed: 2016-12-04 18:49:18 By hackerwahab To nextcloud
High
Vulnerability Details
Hello, My self Abdulwahab, I want to Alert You that Your website is Facing a serious Problem Called : Username Enumeration This Problem is on nextcloud.com/wp-admin We Use wpscan to get username and the username is "frank" After getting username a user can Bruteforce it Using Wpscan and get access to admin panel and upload shell and also get all sub_domain Means Full Server is Hacked! FIX === To Fix this use Wordpress Login Attemptizer Thanks, ABDULWAHAB, Independent Cyber Security Researcher,
Actions
View on HackerOne
Report Stats
  • Report ID: 188205
  • State: Closed
  • Substate: informative
  • Upvotes: 1
Share this report