⏩CMS
Wordpress
The WordPress version is shown in the "generator" meta tag (unless removed by the site). You may search the source code (CTRL-F) for "generator" to see the version. This curl command will also show it. The "-s" flag is for "silent"
basic information
check for vulnerable plugins
check for exploits that match the version of wordpress
vulnerability and plugin scan
enumerate usernames
password attack on discovered usernames
enumerate everything
scan with nmap NSE scripts
Drupal
droopscan
installation:
scanning:
Joomla
joomscan
Get components running on the website
You can also check
If you find components, you can often access the configuration file
Check for vulnerabilities affecting components
Joomlavs
Nikto
A free web application vulnerability scanner preinstalled on kali linux.
Last updated