From c441ff81a1351ec80084ddb62cc9483f1bb4784f Mon Sep 17 00:00:00 2001 From: Tom Sellers Date: Fri, 1 May 2015 17:05:31 -0500 Subject: [PATCH] Update comment in wordpress/version.rb The comment 'All versions are vulnerable' makes sense on line 163 where there is no introduced or fixed version. On line 175 though there is a fixed version, just no introduced version. Adjusting comment text. --- lib/msf/http/wordpress/version.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/msf/http/wordpress/version.rb b/lib/msf/http/wordpress/version.rb index 0358d7cbbf..f3dc60cab9 100644 --- a/lib/msf/http/wordpress/version.rb +++ b/lib/msf/http/wordpress/version.rb @@ -172,7 +172,7 @@ module Msf::HTTP::Wordpress::Version # Version older than fixed version if Gem::Version.new(version) < Gem::Version.new(fixed_version) if vuln_introduced_version.nil? - # All versions are vulnerable + # Older than fixed version, no vuln introduction date, flag as vuln return Msf::Exploit::CheckCode::Appears # vuln_introduced_version provided, check if version is newer elsif Gem::Version.new(version) >= Gem::Version.new(vuln_introduced_version)