关键漏洞信息 基本信息 Title: Social-Share-Buttons v2.2.3 - SQL Injection EDB-ID: 51116 CVE: N/A Author: nu11secur1ty Type: WEBAPPS Platform: PHP Date: 2023-03-28 Vulnerable App: Social-Share-Buttons v2.2.3 描述 Description: The parameter from the Social Share Buttons-2.2.3 on the WordPress-6.0.2 system appears to be vulnerable to SQL injection attacks. The malicious user can dump-steal the database, which can be used for malicious purposes. 攻击细节 Payload: Type: Time-based blind Required MySQL Version: >= 5.0.12 Time-based Blind Method: Sleep delay attack 重现链接 Reproduce: [](https://github.com/nu11security/CVE-nu11security/tree/main/vendors/WordPress/2022/Social-Share-Buttons-2.2.3) 证明与利用 Proof and Exploit: [](https://streamable.com/m9r76w)