4 ms·
I always preferred the remote code execution search myself personally... https://github.com/search?q=extension%3Aphp+exec+%24_GET&type=Code&ref=searchresults h
by a904guy 13y ago
I always preferred the remote code execution search myself personally...
https://github.com/search?q=extension%3Aphp+exec+%24_GET&type=Code&ref=searchresults https://github.com/search?q=extension%3Aphp+exec+%24_GET&typ...
- a904guy 13y agoCGI Python? Happens... https://github.com/search?q=extension%3Apy+os.system+%22import+cgi%22&type=Code&ref=searchresults https://github.com/search?q=extension%3Apy+os.system+%22impo...
- a904guy 13y agoDjango... https://github.com/search?q=extension%3Apy+os.system+%22request.GET%22&type=Code&ref=searchresults https://github.com/search?q=extension%3Apy+os.system+%22requ...
- fjcaetano 13y agoThe difference is that SQL injection will only happen when using raw queries. System (as you mentioned) or EXEC injections, however, may get out of hand.
- ris 13y agoI only found one exploitable example browsing the first few pages, whereas the majority of the OP's results looked fairly exploitable.
- fjcaetano 13y agoHoly shit! Look at this! This is hilarious! https://github.com/bratliff/engconf/blob/0b8f003edc5f5d25fe1feecd9f39d107958ddd11/staging/wp-content/plugins/ezpz-one-click-backup/functions/ezpz-archive-cmd.php https://github.com/bratliff/engconf/blob/0b8f003edc5f5d25fe1...
- krapp 13y agoOh. And it's for wordpress. Isn't that just fucking wonderful. I would guess looking at the age of the account and the complete lack of documentation that it's a personal project he never really intended to get much scrutiny. I'm sure if someone looked at my github they could find some bad code too. Not that bad though. Edit - made an issue.
- spyder 13y agoAnd it has been already exploited: http://wordpress.org/support/topic/plugin-ezpz-one-click-backup-possible-security-flaw http://wordpress.org/support/topic/plugin-ezpz-one-click-bac...