module
WordPress Symposium Plugin SQL Injection
Disclosed | Created |
---|---|
2015-08-18 | 2018-05-30 |
Disclosed
2015-08-18
Created
2018-05-30
Description
This module exploits a SQL injection vulnerability in the WP Symposium plugin
before 15.8 for WordPress, which allows remote attackers to extract credentials
via the size parameter to get_album_item.php.
before 15.8 for WordPress, which allows remote attackers to extract credentials
via the size parameter to get_album_item.php.
Authors
PizzaHatHacker
Matteo Cantoni goony@nothink.org
Matteo Cantoni goony@nothink.org
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.