Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-13640 PoC — WordPress gVectors wpDiscuz SQL注入漏洞

Source
Associated Vulnerability
Title:WordPress gVectors wpDiscuz SQL注入漏洞 (CVE-2020-13640)
Description:WordPress是WordPress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。gVectors wpDiscuz是使用在其中的一个具有实时讨论功能的响应式评论插件。 WordPress gVectors wpDiscuz 5.3.5及之前版本中存在SQL注入漏洞。远程攻击者可借助wpdLoadMoreComments请求的‘order’参数利用该漏洞执行任意SQL命令。
Description
CVE-2020-13640 - SQL injection in wpDiscuz WordPress plugin <= 5.3.5
File Snapshot

[4.0K] /data/pocs/5317ffd74bee93f10c56ca6d1684f94925451083 └── [3.1K] exploit.py 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.