WPIntell

Source evidence

Schwachstelle in Plugin

BST DSGVO Cookie · support · 2019-04-02T08:45:00+00:00

complaintsentiment
highseverity
0.98relevance
1replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

4 / 25 rows with source links

16.0% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

21 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
loewenherz76 unresolved
Hallo zusammen, mit dem Plugin wurde ein Hacker-Angriff durchgeführt, siehe Logfile: x.x.x.x - - [01/Jan/1970:08:48:04 +0200] "GET /xxx/wp-login.php?action=register HTTP/1.1" 302 - "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" x.x.x.x - - [01/Jan/1970:08:48:06 +0200] "POST /xxx/wp-admin/admin-post.php HTTP/1.1" 302 - "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" x.x.x.x - - [01/Jan/1970:08:48:08 +0200] "POST /xxx/wp-admin/admin-post.php HTTP/1.1" 302 - "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" x.x.x.x - - [01/Jan/1970:08:48:10 +0200] "GET /xxx/wp-login.php?action=register HTTP/1.1" 200 4393 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" x.x.x.x - - [01/Jan/1970:08:48:10 +0200] "POST /xxx/wp-login.php?action=register HTTP/1.1" 302 - "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" x.x.x.x - - [01/Jan/1970:08:48:22 +0200] "GET /xxx/wp-login.php?checkemail=registered HTTP/1.1" 200 4740 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" x.x.x.x - - [01/Jan/1970:08:48:29 +0200] "GET /xxx/wp-login.php?action=rp&key=jeVdPaWXw8ZdlMz5g0an&login=violet1939 HTTP/1.1" 302 - "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" x.x.x.x - - [01/Jan/1970:08:48:31 +0200] "GET /xxx/wp-login.php?action=rp HTTP/1.1" 200 7358 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" x.x.x.x - - [01/Jan/1970:08:48:32 +0200] "POST /xxx/wp-login.php?action=resetpass HTTP/1.1" 200 1916 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" x.x.x.x - - [01/Jan/1970:08:48:41 +0200] "POST /xxx/wp-admin/admin-post.php HTTP/1.1" 302 - "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" x.x.x.x - - [01/Jan/1970:08:48:42 +0200] "POST /xxx/wp-admin/admin-post.php HTTP/1.1" 302 - "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" x.x.x.x - - [01/Jan/1970:08:48:44 +0200] "POST /xxx/wp-login.php HTTP/1.1" 302 - "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" x.x.x.x - - [01/Jan/1970:08:48:52 +0200] "GET /xxx/wp-admin/ HTTP/1.1" 200 138811 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" x.x.x.x - - [01/Jan/1970:08:48:56 +0200] "GET /xxx/wp-admin/plugin-editor.php HTTP/1.1" 200 207999 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" x.x.x.x - - [01/Jan/1970:08:48:58 +0200] "GET /xxx/wp-admin/plugin-editor.php?plugin=bst-dsgvo-cookie/bst.php HTTP/1.1" 200 139312 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" x.x.x.x - - [01/Jan/1970:08:48:59 +0200] "GET /xxx/wp-admin/plugin-editor.php?plugin=bst-dsgvo-cookie/bst.php&file=bst-dsgvo-cookie/includes/enqueue.php HTTP/1.1" 200 128570 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" x.x.x.x - - [01/Jan/1970:08:49:01 +0200] "GET /xxx/wp-admin/plugin-editor.php?plugin=bst-dsgvo-cookie/bst.php&file=bst-dsgvo-cookie/includes/enqueue.php HTTP/1.1" 200 128570 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" Bei einem anderen Plugin gab es im November 2018 ein ähnliches Problem. Vielleicht wird die gleiche Schwachstelle ausgenutzt, siehe Link: VG Loewenherz This topic was modified 7 years, 1 month ago by loewenherz76 . This topic was modified 7 years, 1 month ago by loewenherz76 . This topic was modified 7 years, 1 month ago by loewenherz76 . This topic was modified 7 years, 1 month ago by Jan Dembowski . The page I need help with: [ log in to see the link] Danke für den Hinweis! Werde das plugin sofort deinstallieren. Gibt mir beim update auch Fehlermeldung raus: Missing archive file ‘/tmp/bst-dsgvo-cookie-wsaQFX.tmp’ BG guckmada

Comments

1 shown
guckmada 2019-04-11T14:31:00+00:00

Danke für den Hinweis! Werde das plugin sofort deinstallieren. Gibt mir beim update auch Fehlermeldung raus: Missing archive file ‘/tmp/bst-dsgvo-cookie-wsaQFX.tmp’ BG guckmada