code.wordpress.net subdomain Takeover

Disclosed: 2018-03-11 20:53:27 By sniperpex To wordpress
Medium
Vulnerability Details
Hy Wordpress sec i found as it is posible to takeover this domain http://code.wordpress.net when you navigate it you will get this error msg: Warning! Domain mapping upgrade for this domain not found. Please log in and go to the Domains Upgrades page of your blog to use this domain. $ host code.wordpress.net code.wordpress.net is an alias for wpprojects.wordpress.com. wpprojects.wordpress.com is an alias for lb.wordpress.com. lb.wordpress.com has address 192.0.78.13 lb.wordpress.com has address 192.0.78.12 ## Impact The attacker can takeover this subdomain
Actions
View on HackerOne
Report Stats
  • Report ID: 295330
  • State: Closed
  • Substate: resolved
  • Upvotes: 9
Share this report