Wordpress + SQL injection + shell

Company name is hidden 01 January 2017, 22:01

Detailed information

Have SQL injection on site.
By using this weakness possible Steal sensitive information from the site (Passwords, site structure, etc.)
Sql inject here : http://siteaddress.com/search.php?id=QURAN%20Ata-Ana%20Haqda%27
Shell adress: siteaddress.com/oc-content/themes/pencarian/404.php

Comments

  • 17 April 2017, 09:31
    Vulnerability status
    Have not any information from source

  • 05 January 2017, 20:04
    Vulnerability status
    Sended e-mail to source about vulnerability

  • 03 January 2017, 17:10
    Added point to Vulnerability
    Moderator gave 8 point from 10 to vulnerability

  • 03 January 2017, 17:07
    Vulnerability status
    Confirmed by Moderator

  • 01 January 2017, 22:01
    Vulnerability added
    Vulnerability added to BUGemot