==================================================================================================================================== | # Title : WordPress profile builder 3.0.5 SQL Injection Vulnerability | | # Author : indoushka | | # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 69.0.3(32-bit) | | # Vendor : https://fr.wordpress.org/plugins/profile-builder/ | | # Dork : " " | ==================================================================================================================================== poc : [+] Dorking İn Google Or Other Search Enggine. [+] http://127.0.0.1/artscouncilofwilmingtonorg/members/member_detail.php?id=1772 <====| inject here [+] http://127.0.0.1/artscouncilofwilmingtonorg/members/login.php <====| Login Greetings to :========================================================================================================================= | jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm * thelastvvv *Zigoo.eg | | =======================================================================================================================================