# Shop Manager+ SQL注入漏洞
## 概述
Flat Shipping Rate by City for WooCommerce 插件中存在基于时间的 SQL 注入漏洞,影响 WordPress 平台。
## 影响版本
所有版本至 1.0.3(含)。
## 细节
漏洞源于对 'cities' 参数未充分转义,且 SQL 查询未使用预编译等安全处理方式。经认证的攻击者可利用该参数注入恶意 SQL 语句。
## 影响
拥有 Shop Manager 或更高权限的攻击者可执行时间盲注,从数据库中提取敏感信息。
是否为 Web 类漏洞: 未知
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
标题: ERROR: The request could not be satisfied -- 🔗来源链接
标签:
神龙速读:
- **Status Code**: 403 ERROR
- **Message**: The request could not be satisfied.
- **Reason**: Request blocked. The server for the app or website is not available at this time due to excessive traffic or a configuration error.
- **Action Suggestion**: Try again later or contact the app or website owner. If distributing content through CloudFront, review the CloudFront documentation for troubleshooting steps.
- **Generated by**: cloudfront (CloudFront)
- **Request ID**: pCaJn0c-yd6TBx1u74oOhRcygIaela-iAqsBswLin1qN_N5DPFzzpg==
Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.