WordPress 插件 WP Visitor Statistics(实时流量)在 8.7 及以下所有版本中存在通用 SQL 注入漏洞,原因是未对用户提供的参数 进行充分的转义,且现有 SQL 查询缺乏适当的预处理。这使得未经身份验证的攻击者能够将额外的 SQL 查询注入到已有的查询中,从而从数据库中提取敏感信息。 该漏洞属于二阶 SQL 注入:未经身份验证的攻击者向 跟踪端点提交一个精心构造的 Referer URL,该 URL 的原始未转义值会被持久化存储到 表中。当管理员下次访问“流量来源”(Traffic
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| osamaesh | WP Visitor Statistics (Real Time Traffic) | 0 ~ 8.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet