M
У человека полный доступ к БД. Может хоть пользователя создать, хоть пароль любому поменять. Но не может пролиться, потому что в конфиге прописано, что модификация файлов темы и тд итп запрещена.
Size: a a a
M
i
test
(test
text NOT NULLtest
LIMIT 0 , 30;M
test
(test
text NOT NULLtest
LIMIT 0 , 30;⟁ᴡ
M
AM
M
WordPress/Dompdf/RCE1 <= 0.8.5+ rce __destruct *
WordPress/Dompdf/RCE2 0.7.0 <= 0.8.4 rce __destruct *
WordPress/Guzzle/RCE1 4.0.0 <= 6.4.1+ rce __toString *
WordPress/Guzzle/RCE2 4.0.0 <= 6.4.1+ rce __destruct *
WordPress/P/EmailSubscribers/RCE1 4.0 <= 4.4.7+ rce __destruct *
WordPress/P/EverestForms/RCE1 1.0 <= 1.6.7+ rce __destruct *
WordPress/P/WooCommerce/RCE1 3.4.0 <= 4.1.0+ rce __destruct *
WordPress/P/YetAnotherStarsRating/RCE1 ? <= 1.8.6 rce __destruct *
⟁ᴡ
load data local infile "/etc/passwd" into table test FIELDS TERMINATED BY '\n';
⟁ᴡ
ERROR 1290 (HY000): The MySQL server is running with the --secure-file-priv option so it cannot execute this statement
AM
WordPress/Dompdf/RCE1 <= 0.8.5+ rce __destruct *
WordPress/Dompdf/RCE2 0.7.0 <= 0.8.4 rce __destruct *
WordPress/Guzzle/RCE1 4.0.0 <= 6.4.1+ rce __toString *
WordPress/Guzzle/RCE2 4.0.0 <= 6.4.1+ rce __destruct *
WordPress/P/EmailSubscribers/RCE1 4.0 <= 4.4.7+ rce __destruct *
WordPress/P/EverestForms/RCE1 1.0 <= 1.6.7+ rce __destruct *
WordPress/P/WooCommerce/RCE1 3.4.0 <= 4.1.0+ rce __destruct *
WordPress/P/YetAnotherStarsRating/RCE1 ? <= 1.8.6 rce __destruct *
AM
WordPress/Dompdf/RCE1 <= 0.8.5+ rce __destruct *
WordPress/Dompdf/RCE2 0.7.0 <= 0.8.4 rce __destruct *
WordPress/Guzzle/RCE1 4.0.0 <= 6.4.1+ rce __toString *
WordPress/Guzzle/RCE2 4.0.0 <= 6.4.1+ rce __destruct *
WordPress/P/EmailSubscribers/RCE1 4.0 <= 4.4.7+ rce __destruct *
WordPress/P/EverestForms/RCE1 1.0 <= 1.6.7+ rce __destruct *
WordPress/P/WooCommerce/RCE1 3.4.0 <= 4.1.0+ rce __destruct *
WordPress/P/YetAnotherStarsRating/RCE1 ? <= 1.8.6 rce __destruct *
AM
i
AM
i
i
AM
i