
Du weißt, dass ein Plugin einen PHP-Object-Exploit hat, musst aber herausfinden, welche Bibliothek du verwenden sollst?
Du hast ein bekanntes Plugin mit einem PHP-Objekt-Exploit, musst aber herausfinden, welche Bibliothek du verwenden kannst, um das Problem auszunutzen und mit phpggc auszuführen.
Das sollte dir weiterhelfen.
$ python3 finder.py -u http://wordpress.lan -f wp-plugins.lst
Processing URLs: 100%|█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 26/26 [00:00<00:00, 26.74it/s]
Found the following plugins:
http://wordpress.lan/wp-content/plugins/updraftplus/readme.txt
Checking Wordpress SVN for vendor folder.
Vendor Folder found at http://plugins.svn.wordpress.org/updraftplus/trunk/vendor/
Checking for known libraries for phpgcc inside vendor folder.
You may be able to use the following Guzzle with this updraftplus plugin.
You may be able to use the following Symfony with this updraftplus plugin.
You may be able to use the following PHPSecLib with this updraftplus plugin.