WordPress 的 WP Directory Kit 插件在所有 1.5.9 及更早版本中,存在一个基于时间的 SQL 注入漏洞,该漏洞出现在“display_name”个人资料字段(第二阶注入)中。原因是用户提供的参数缺乏足够的转义处理,且现有 SQL 查询中缺乏足够的预处理机制。这使得拥有订阅者(Subscriber)及以上权限的认证攻击者能够向已存在的 SQL 查询中附加额外的 SQL 查询,从而从数据库中提取敏感信息。 这是一个第二阶注入漏洞:订阅者可以通过自己的个人资料页面存储一个包含单引号的 ,而
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wpdirectorykit | WP Directory Kit | ≤ 1.5.9 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpdirectorykit | WP Directory Kit | 0 ~ 1.5.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet