CVE-2018-6389
Dashboard / Vulnerabilities / CVE-2018-6389
CVE-2018-6389
Summary:
Details: In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.
References: http://www.securityfocus.com/bid/103060, http://www.securitytracker.com/id/1040347, https://github.com/WazeHell/CVE-2018-6389, https://wpvulndb.com/vulnerabilities/9021, https://baraktawily.blogspot.fr/2018/02/how-to-dos-29-of-world-wide-websites.html, https://github.com/UltimateHackers/Shiva, https://thehackernews.com/2018/02/wordpress-dos-exploit.html, https://www.exploit-db.com/exploits/43968/
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
