Re: WordPress feed plugin Sql Injection

看板Bugtraq作者時間12年前 (2013/07/09 12:32), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串2/2 (看更多)
--dCSxeJc5W8HZXZrD Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Tue, Jul 02, 2013 at 12:01:15PM +0000, iedb.team@gmail.com wrote: > The WordPress feed plugin suffers from a Sql Injection vulnerability. >=20 > ################################# >=20 > # Iranian Exploit DataBase >=20 > # http://exploit.iedb.ir >=20 > ################################# >=20 > # Exploit Title : WordPress feed plugin Sql Injection >=20 > # Author : Iranian Exploit DataBase >=20 > # Discovered By : IeDb >=20 > # Email : IeDb.Team@Gmail.com >=20 > # Home : http://exploit.iedb.ir >=20 > # Software Link : http://wordpress.org/ >=20 > # Security Risk : High >=20 > # Tested on : Linux >=20 > # Dork : inurl:wp-content/plugins/feed/ >=20 > ################################# >=20 > # Exploit : >=20 > # http://www.Site.com/wp-content/plugins/feed/news_dt.php?nid=3D[Sql] >=20 > # Dem0 : >=20 > # http://easy2remind.com/newsworld/wp-content/plugins/feed/news_dt.php?ni= d=3D257[Sql] >=20 > ################################# >=20 > ################################# >=20 > # Exploit Archive =3D http://exploit.iedb.ir/exploits-176.html >=20 > ################################# Could you give us proper software link, thanks. There is no such plugin in WordPress plugin repository[1]. Is this non-free plugin? Searching for inurl:"/wp-content/plugins/feed/news_dt.php" only finds easy2remind.com web= site. 1: http://plugins.svn.wordpress.org/feed/ --- Henri Salo --dCSxeJc5W8HZXZrD Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlHbFsMACgkQXf6hBi6kbk8+4QCgpEqaHw2J5qFCFN6f9pWQg0ff KNwAmwS1R4GuK9Zq1rmQXpvqAJy6dBUj =HjEf -----END PGP SIGNATURE----- --dCSxeJc5W8HZXZrD--
文章代碼(AID): #1Hsv930x (Bugtraq)
文章代碼(AID): #1Hsv930x (Bugtraq)