""ET WEB_SPECIFIC_APPS Wordpress Host Header Injection (CVE-2016-10033) M2""

SID: 2024278

Revision: 1

Class Type: web-application-attack

Metadata: affected_product Wordpress, attack_target Web_Server, created_at 2017_05_05, cve CVE_2016_10033, deployment Perimeter, signature_severity Major, updated_at 2017_05_05

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HTTP_SERVERS

Destination Port: $HTTP_PORTS

Flow: to_server,established

Contents:

  • Value: "action=lostpassword"

Within:

PCRE: "/^Host\x3a[^\r\n]+?[\x28\x29\x27\x22\x7b\x7d]/Hmi"

Special Options:

  • http_uri

  • nocase

  • fast_pattern

source