
Exploit de upload arbitrário de arquivos não autenticado para o plugin WooCommerce Return Refund and Exchange (CVE-2022-4047). Escaneia alvos, faz upload de webshell e registra URLs vulneráveis.
Return Refund and Exchange For WooCommerce < 4.0.9 - Upload Arbitrário de Arquivo Não Autenticado
@@@@@@@ @@@ @@@ @@@@@@@@ @@@@@@ @@@@@@@@ @@@@@@ @@@@@@ @@@ @@@@@@@@ @@@ @@@@@@@@
@@@@@@@@ @@@ @@@ @@@@@@@@ @@@@@@@@ @@@@@@@@@@ @@@@@@@@ @@@@@@@@ @@@@ @@@@@@@@@@ @@@@ @@@@@@@@
!@@ @@! @@@ @@! @@@ @@! @@@@ @@@ @@@ @@!@! @@! @@@@ @@!@! @@!
!@! !@! @!@ !@! @!@ !@! @!@!@ @!@ @!@ !@!!@! !@! @!@!@ !@!!@! !@!
!@! @!@ !@! @!!!:! @!@!@!@!@ !!@ @!@ @! !@! !!@ !!@ @!@!@!@!@ @!! @!! @!@ @! !@! @!! @!! @!!
!!! !@! !!! !!!!!: !!!@!@!!! !!: !@!!! !!! !!: !!: !!!@!@!!! !!! !@! !@!!! !!! !!! !@! !!!
:!! :!: !!: !!: !:! !!:! !!! !:! !:! :!!:!:!!: !!:! !!! :!!:!:!!: !!:
:!: ::!!:! :!: :!: :!: !:! :!: :!: !:::!!::: :!: !:! !:::!!::: :!:
::: ::: :::: :: :::: :: ::::: ::::::: :: :: ::::: :: ::::: ::: ::::::: :: ::: ::
:: :: : : : :: :: :: : ::: : : : : :: : ::: :: : ::: ::: : : : : ::: : :
usage: exploit.py [-h] [-u URL] [-f FILE]
CVE-2022-4047 - Return Refund and Exchange For WooCommerce < 4.0.9 - Upload Arbitrário de Arquivo Não Autenticado (Upload em Massa de PHP)
options:
-h, --help mostra esta mensagem de ajuda e sai
-u URL, --url URL url
-f FILE, --file FILE lista de urls
requests
pip3 install requestspython3 exploit.py -u urlpython3 exploit.py -f file_path