bugtraq
[Top] [All Lists]

WordPress Search Function SQL-Injection

To: bugtraq@securityfocus.com, full-disclosure@lists.grok.org.uk, vuln-dev@securityfocus.com, webappsec@securityfocus.com
Subject: WordPress Search Function SQL-Injection
From: SaMuschie <samuschie@yahoo.de>
Date: Tue, 27 Feb 2007 21:39:55 +0100 (CET)
Delivered-to: sp-com-lists@consult.net
Delivered-to: bugtraq-list@securepoint.com
Delivered-to: mailing list bugtraq@securityfocus.com
Delivered-to: moderator for bugtraq@securityfocus.com
Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.de; h=Message-ID:X-YMail-OSG:Received:Date:From:Subject:To:MIME-Version:Content-Type:Content-Transfer-Encoding; b=Pr0YCrrlvN+bdcutBLVwB67FgtQLqAdYLKkNzKQ8QYtzLFa97CUBQbSdAA2SGiVRz2X5TdJ8ZnFHIIAcimqBLUcKUCtAWY/tDfoRHvt8m/NL6MQ5IQtjb7yXKXh831OvJIlmtlP5tWnlBjpO8bpeZTH+FulENdLbrPGDkw726Rc= ;
List-help: <mailto:bugtraq-help@securityfocus.com>
List-id: <bugtraq.list-id.securityfocus.com>
List-post: <mailto:bugtraq@securityfocus.com>
List-subscribe: <mailto:bugtraq-subscribe@securityfocus.com>
List-unsubscribe: <mailto:bugtraq-unsubscribe@securityfocus.com>
Mailing-list: contact bugtraq-help@securityfocus.com; run by ezmlm
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

+--------------------------------------- -  -- -
| SaMuschie Research Labs proudly presents . . .
+-------------------------------------------  -- -  -  
| Application: wordpress
| Version: <= 2.1.1
| Vuln./Exploit Type: SQL-Injection
| Status: 0day
+----------------------------------------- --  -  -  
| Discovered by: Samenspender
| Released: 20070227
| SaMuschie Release Number: 2
+------------------------------- -  -- -

Searching for a single ,,comma,, generates a sql error message.

e.g.:

http://wordpress-deutschland.org/?s=,

results in:

    "WordPress Datenbank-Fehler: [You have an error in your SQL syntax; check 
the
manual that corresponds to your MySQL server version for the right syntax to 
use near ') AND (post_type = 'post' AND (post_status = 'publish')) ORDER BY 
post_date DE' at line 1] 
SELECT SQL_CALC_FOUND_ROWS wpdorg_posts.* FROM wpdorg_posts WHERE 1=1 AND () 
AND (post_type = 'post' AND (post_status = 'publish')) ORDER BY post_date DESC
LIMIT 0, 10"

+-----------------------------  -- -
| Lameness Disclaimer
+------------------------------------- - -- -  -  
| SaMuschie Research Labs was found to publish
| vulnerabilities within well known software products,
| which are easy to discover and exploit.
| 
| SaMuschie researchers just spend a minimum of time
| and knowledge for each vulnerability. Hence readers of 
| this advisory are requested not to ask any questions
| to the researchers.... they don't know the answer ;) 
+----------------------------------  - --  - -
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFF5GSdMFgfGpQK8VERAvOWAJwLms5H6b4So3tO19lc3eHMGeNvLwCdHAP8
ZfylSi7g8HINHkpBYzYgUqE=
=fBdH
-----END PGP SIGNATURE-----


                
___________________________________________________________ 
Telefonate ohne weitere Kosten vom PC zum PC: http://messenger.yahoo.de

<Prev in Thread] Current Thread [Next in Thread>