使用 Docker 搭建 CVE-2024-1071 漏洞环境
🎯 想要练习新的 WordPress CVE 吗?请按照以下说明操作。
搭建实验环境
- 安装 Docker:https://docs.docker.com/get-docker/
- 克隆项目:
git clone https://github.com/Trackflaw/CVE-2024-1071-Docker.git。
- 进入项目目录:
cd CVE-2024-1071-Docker
- 启动 Docker Compose 文件:
docker compose up -d。
- 使用
root:root 凭据连接到 http://localhost。
- 在 http://localhost/wp-admin/plugins.php 中激活插件。
- 在 http://localhost/wp-admin/admin.php?page=um_options&tab=misc 中激活“允许使用自定义表存储账户元数据”选项。
概念验证 (PoC)
https://github.com/Trackflaw/CVE-2024-1071-Docker/assets/78696986/e4c31c76-e7e2-415f-8142-15325c179f9b
自动化
许多 PoC 已在线提供,可自动化利用此漏洞: