Class: WPScan::DB::VulnApi

Inherits:
Object
  • Object
show all
Defined in:
lib/wpscan/db/vuln_api.rb

Overview

WPVulnDB API

Constant Summary collapse

NON_ERROR_CODES =
[200, 403].freeze

Class Attribute Summary collapse

Class Method Summary collapse

Class Attribute Details

.tokenObject

Returns the value of attribute token.



10
11
12
# File 'lib/wpscan/db/vuln_api.rb', line 10

def token
  @token
end

Class Method Details

.default_request_paramsHash

Note:

Those params can not be overriden by CLI options

Returns:

  • (Hash)


75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
# File 'lib/wpscan/db/vuln_api.rb', line 75

def self.default_request_params
  @default_request_params ||= begin
    params = Browser.instance.default_request_params.merge(
      headers: {
        'User-Agent' => Browser.instance.default_user_agent,
        'Authorization' => "Token token=#{token}"
      }
    )

    if ParsedCli.proxy_target_only
      params.delete(:proxy)
      params.delete(:proxyuserpwd)
    end

    params
  end
end

.get(path, params = {}) ⇒ Hash

Parameters:

  • path (String)
  • params (Hash) (defaults to: {})

Returns:

  • (Hash)


22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
# File 'lib/wpscan/db/vuln_api.rb', line 22

def self.get(path, params = {})
  return {} unless token
  return {} if path.end_with?('/latest') # Remove this when api/v4 is up

  # Typhoeus.get is used rather than Browser.get to avoid merging irrelevant params from the CLI
  res = Typhoeus.get(uri.join(path), default_request_params.merge(params))

  return {} if [404, 429].include?(res.code)
  return JSON.parse(res.body) if NON_ERROR_CODES.include?(res.code)

  raise Error::HTTP, res
rescue Error::HTTP => e
  retries ||= 0

  if (retries += 1) <= 3
    @default_request_params[:headers]['X-Retry'] = retries

    sleep(1)
    retry
  end

  { 'http_error' => e }
rescue JSON::ParserError => e
  # API returned non-JSON response (HTML, plain text, etc.)
  { 'parse_error' => e }
end

.plugin_data(slug) ⇒ Hash

Returns:

  • (Hash)


50
51
52
# File 'lib/wpscan/db/vuln_api.rb', line 50

def self.plugin_data(slug)
  get("plugins/#{slug}")&.dig(slug) || {}
end

.statusHash

Returns:

  • (Hash)


65
66
67
68
69
70
71
# File 'lib/wpscan/db/vuln_api.rb', line 65

def self.status
  json = get('status', params: { version: WPScan::VERSION }, cache_ttl: 0)

  json['requests_remaining'] = 'Unlimited' if json['requests_remaining'] == -1

  json
end

.theme_data(slug) ⇒ Hash

Returns:

  • (Hash)


55
56
57
# File 'lib/wpscan/db/vuln_api.rb', line 55

def self.theme_data(slug)
  get("themes/#{slug}")&.dig(slug) || {}
end

.uriAddressable::URI

Returns:

  • (Addressable::URI)


14
15
16
# File 'lib/wpscan/db/vuln_api.rb', line 14

def self.uri
  @uri ||= Addressable::URI.parse('https://wpscan.com/api/v3/')
end

.wordpress_data(version_number) ⇒ Hash

Returns:

  • (Hash)


60
61
62
# File 'lib/wpscan/db/vuln_api.rb', line 60

def self.wordpress_data(version_number)
  get("wordpresses/#{version_number.tr('.', '')}")&.dig(version_number) || {}
end