WordPress Plugin WA Form Builder SQL...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Description: Type user access: any user. $_POST[ ‘wa_forms_Id’ ] is not escaped. WAFormBuilder_ui_output() is accessible for any user. ### File / Code: Path: /wp-content/plugins/wa-form-builder/main.php ``` global $wpdb; echo 'SELECT * FROM '.$wpdb->prefix.'wap_wa_form_builder WHERE Id = '.$_REQUEST['wa_forms_Id']; $form_attr = $wpdb->get_row('SELECT * FROM '.$wpdb->prefix.'wap_wa_form_builder WHERE Id = '.$_REQUEST['wa_forms_Id']); $user_fields .= '<table width="100%" cellpadding="3" cellspacing="1" style="background:#e7e7e7; color:#666;">'; foreach($_POST as $key=>$val) { if( $key!='action' && $key!='current_page' && $key!='ajaxurl' && $key!='page_id' && $key!='wa_forms_Id' && $key!='submit' ) { $user_fields .= '<tr>'; $user_fields .= ' <td bgcolor="#f2f2f2" width="20%">'.IZC_Functions::unformat_name(str_replace('dynamic_forms','',$key)).'</td> <td bgcolor="#FFFFFF" >'.IZC_Functions::unformat_name($val).'</td>'; $user_fields .= '</tr>'; $insert =...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息