Web Hack List

Collected research

Persistent SQL Injection

Óâåäîìëåíèå î áåçîïàñíîñòè: New vulnerabilities in CapCC for WordPress

MustLive's advisory on the WordPress CapCC captcha plugin 1.0. CSRF on the plugin's option page drives an SQL injection whose payload persists in the captcha table and re-fires on every page view — self-inflicted DoS — which he presents as the first Persistent SQLi.

Record

Document
Óâåäîìëåíèå î áåçîïàñíîñòè: New vulnerabilities in CapCC for WordPress
Researcher
MustLive
Published by
securityvulns.ru
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of MustLive, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .