WordPress诸多插件爆出高危漏洞
1.WordPress SH Slideshow plugin <= 3.1.4 SQL Injection Vulnerability
Exploit Title: WordPress SH Slideshow plugin <= 3.1.4 SQL Injection Vul......
1.WordPress SH Slideshow plugin <= 3.1.4 SQL Injection Vulnerability
Exploit Title: WordPress SH Slideshow plugin <= 3.1.4 SQL Injection Vul......
1.WordPress SH Slideshow plugin <= 3.1.4 SQL Injection Vulnerability
Exploit Title: WordPress SH Slideshow plugin <= 3.1.4 SQL Injection Vul......
作者:晴天小铸
测试环境:discuz X1.5+nginx 1.0
漏洞文件source/function/function_core.php,代码:
$_G['setting']['domain']['app'][......