Bot for JCE able to upload malicious file to up-to-date WordPress site
-
I have a WordPress site hosted on a CloudLinux server, and for some reason malicious scripts were uploaded to my .cagefs/tmp folder by a bot.
File timestamps and the following log timestamps match exactly, so I’m puzzled how a hack/exploit for Joomla (afaik) worked on a WP install?
70.35.202.197 - - [03/Mar/2016:03:02:50 -0500] "POST /index.php?option=com_jce&task=plugin&plugin=imgmanager&file=imgmanager&method=form&cid=20&6bc427c8a7981f4fe1f5ac65c1246b5f=cf6dd3cf1923c950586d0dd595c8e20b HTTP/1.1" 200 0 "-" "BOT/0.1 (BOT for JCE)" 70.35.202.197 - - [03/Mar/2016:03:02:58 -0500] "POST /index.php?option=com_jce&task=plugin&plugin=imgmanager&file=imgmanager&method=form&cid=20&6bc427c8a7981f4fe1f5ac65c1246b5f=cf6dd3cf1923c950586d0dd595c8e20b HTTP/1.1" 200 0 "-" "BOT/0.1 (BOT for JCE)" 70.35.202.197 - - [03/Mar/2016:03:03:13 -0500] "POST /index.php?option=com_jce&task=plugin&plugin=imgmanager&file=imgmanager&method=form&cid=20&6bc427c8a7981f4fe1f5ac65c1246b5f=cf6dd3cf1923c950586d0dd595c8e20b HTTP/1.1" 200 0 "-" "BOT/0.1 (BOT for JCE)" 70.35.202.197 - - [03/Mar/2016:03:03:21 -0500] "POST /index.php?option=com_jce&task=plugin&plugin=imgmanager&file=imgmanager&method=form&cid=20&6bc427c8a7981f4fe1f5ac65c1246b5f=cf6dd3cf1923c950586d0dd595c8e20b HTTP/1.1" 200 0 "-" "BOT/0.1 (BOT for JCE)"
Viewing 3 replies - 1 through 3 (of 3 total)
Viewing 3 replies - 1 through 3 (of 3 total)
The topic ‘Bot for JCE able to upload malicious file to up-to-date WordPress site’ is closed to new replies.