
Exploit Python pour CVE-2019-14314 : injection SQL authentifiée dans le plugin WordPress NextGEN Gallery 3.2.10, extrayant les hachages de mots de passe de la base de données.
CVE-2019-14314 - NextGEN Gallery 3.2.10 Injection SQL authentifiée
usage: cve_2019_14314.py [-h] url login_user login_pass username
CVE-2019-14314 Hash Extractor
positional arguments:
url Wordpress blog URL
login_user Username to login with
login_pass Password to login with
username Username to extract Password Hash from
optional arguments:
-h, --help show this help message and exit
Crédit : https://www.fortinet.com/blog/threat-research/wordpress-plugin-sql-injection-vulnerability.html