🩸
Pentesting Notes
search
Ctrlk
  • ㊙️r3dcl1ffchevron-right
    • 🔬Enumerationchevron-right
      • FTP 21
      • SSH 22
      • Telnet 23 - 2323
      • SMTP 25
      • DNS 53
      • 80 httpchevron-right
        • /phpbash.php
        • inspecting source | Devtools
        • toolbar that allows to run commands on target
        • Wordpress Enumerationchevron-right
          • Extra commands
          • WPScan one-liners
          • Plugins & Themes exploitationchevron-right
          • CVE-2020-35489 Contact Form 7
          • one-liners
          • CVE-2023-23488
          • nmap
          • Common directories
          • MoveStore API Auth bypass
        • Drupal
        • Koken CMS
        • Codiad
        • /.git
        • Subrion CMS 4.2.1
        • Fuel CMS
        • phpmyadmin
        • /cgi-bin Shellshock
        • Sar2HTML
        • Cute News
        • Nagios
        • Joomla
        • advanced_component_system
        • webdav
        • OTRS 5.0
        • Apache James
        • Ovidentia
        • Cuppa CMS
        • Phreebooks
        • Elastix 2.2.0
        • ApPHP MicroBlog
        • MongoDB 2.2.3
        • CMS Made Simple 2.2.13
        • Jinja2
        • Webmin
        • robots.txt
        • BuilderEngine 3.5.0 Remote Code Execution via elFinder 2.0
        • Squid proxy
        • simfony CMS
        • C-Panel Reflected XSS - CVE-2023-294
        • vBulletin <= 5.6.9: Pre-authentication Remote Code Execution
      • 88 Kerberos
      • Pop 110-995
      • RPC 111
      • Ident 113
      • NNTP 119
      • NETBios 137-138
      • SMB-Samba 135-139 445
      • MSRPC 135
      • SNMP 161
      • LDAP - 389,636
      • Modbus 502
      • OpenSSL 1337
      • Ms-SQL 1433
      • Oracle Listener 1521 1522 1529
      • NFS 2049
      • MySql 3306
      • RDP 3389
      • ADB Android Debug Bridge 5555
      • WinRM 5985 5986
      • VNC 5800 5900
      • Redis 6379
      • Unreal IRC 6667
      • Tomcat 8080
      • MongoDB 27017
      • Webapp Enum Methodology
      • IIS
    • 🧨Exploitation (deprecated node)chevron-right
    • 🈲Privescchevron-right
    • 🖥️CLI-Fuchevron-right
    • 🎯OSINTchevron-right
    • 🛠️Toolschevron-right
    • 🟦Active Directorychevron-right
    • 🪓Sysadminchevron-right
    • 🗒️Pentesting Checklist(s)chevron-right
    • 🕷️WebApp Pentestchevron-right
    • 🌩️Cloudchevron-right
    • 🧠Threat Intelchevron-right
    • 📟IoT / IIoTchevron-right
    • 🏭ICS/OT - SCADAchevron-right
    • 🩻Private Templateschevron-right
    • 🐞BBP
    • 📱Mobilechevron-right
  • Daily Syncs
    • Design Standupschevron-right
  • Weekly Syncs
    • Company Weeklieschevron-right
  • Other Regulars
    • Company Weeklieschevron-right
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. ㊙️r3dcl1ffchevron-right
  2. 🔬Enumerationchevron-right
  3. 80 http

Wordpress Enumeration

Enumeration one-liners and exploitation of vulnerable plugins

Extra commandschevron-rightWPScan one-linerschevron-rightPlugins & Themes exploitationchevron-rightCVE-2020-35489 Contact Form 7chevron-rightone-linerschevron-rightCVE-2023-23488chevron-rightnmapchevron-rightCommon directorieschevron-rightMoveStore API Auth bypasschevron-right
Previoustoolbar that allows to run commands on targetchevron-leftNextExtra commandschevron-right

Last updated 3 years ago