漏洞信息详情
Pradeep Makone wordpress Support Plus Responsive Ticket System SQL注入漏洞
漏洞简介
Pradeep Makone wordpress Support Plus Responsive Ticket System是一套使用在WordPress中的响应式票务系统。
Pradeep Makone wordpress Support Plus Responsive Ticket System 9.0.2及之前的版本中存在SQL注入漏洞。远程攻击者可利用该漏洞执行SQL命令。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://wordpress.org/plugins/wp-support-plus-responsive-ticket-system/#developers
参考网址
来源:MISC
链接:https://github.com/00theway/exp/blob/master/wordpress/wpsupportplus.md
来源:CONFIRM
链接:https://wordpress.org/plugins/wp-support-plus-responsive-ticket-system/#developers
受影响实体
- Wpsupportplus Wp_support_plus_responsive_ticket_system:9.0.2:~~~Wordpress~~<!--2000-1-1-->
补丁
- Pradeep Makone wordpress Support Plus Responsive Ticket System SQL注入漏洞 的修复措施<!--2018-3-14-->
还没有评论,来说两句吧...