what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

wp206-disclose.txt

wp206-disclose.txt
Posted Jan 14, 2007
Authored by xy7

WordPress versions 2.1Alpha and 2.0.6 and below suffer from information disclosure flaws.

tags | advisory, info disclosure
SHA-256 | adfae8db1766a8f08d12248b31178778321123de1d0b3adecc24e59f6089943d

wp206-disclose.txt

Change Mirror Download
Wordpress Full Path disclosure and disclosure of Table Prefix Weakness

Description:

Affected system:
WordPress 2.1Alpha 3(SVN:4662)
WordPress =>2.0.6

xy7 has discovered a weakness in WordPress, which can be exploited by

malicious people to disclose SQL information and Wordpress Full Path.

The problem is that SQL error messages are returned to the user. This can

be exploited to disclose the configured table prefix via an invalid "m"

parameter passed in index.php.

Example:
http://[host]/index.php?m[]=


You will see return information like this:
Warning: rawurlencode() expects parameter 1 to be string, array given in

[path]\wp-includes\classes.php on line 227

WordPress 数据库错误: [Unknown column 'Arra' in 'where clause']
SELECT SQL_CALC_FOUND_ROWS wp_posts.* FROM wp_posts WHERE 1=1 AND YEAR

(post_date)=Arra AND (post_type = 'post' AND (post_status = 'publish' OR

post_status = 'private')) ORDER BY post_date DESC LIMIT 0, 10


Solution:
Edit the source use is_array() function to Inspection Var "$m"

Provided and/or discovered by:
Xy7 of Bug.Center.Team found the vulnerability
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close