Loading HuntDB...

xmlrpc.php on mariadb.org can lead to DDOS and brute force attacks

Low
M
MariaDB
Submitted None

Team Summary

Official summary from MariaDB

XMLRPC was enabled and accessible on our website. Since we don't need any of the functionality provided by the Wordpress XMLRPC protocol, we were already trying to block XMLRPC requests to our site via our web server configuration, however, due to a syntactic error our enforcing rule did not apply.

Reported by indoappsec

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Uncontrolled Resource Consumption