WordPress PAM²å¼þÔ¶³ÌºÅÁîÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-08-30

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-15877£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Plainview Activity Monitor plugin version <= 20161228


·ì϶¸ÅÊö


WordPress ²å¼þPlainview Activity Monitor±»ÆØ³ö´æÔÚÒ»¸öÔ¶³ÌºÅÁîÖ´Ðзì϶¡£Plainview Activity Monitor ÊÇÒ»¿îÍøÕ¾Óû§»î¶¯¼à¿Ø²å¼þ¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòurl¡°/wp-admin/admin.php?page=plainview_activity_monitor&tab=activity_tools¡±·¢Ë;«ÐÄ»ú¹ØµÄ¡°ip¡±²ÎÊýÀ´ÀûÓø÷ì϶¡£´Ë·ì϶µÄ³É¹¦ÀûÓñØÒªÌØÈ¨£¬µ«ÊÇ´æÓи÷ì϶µÄ²å¼þ°æ±¾Ò²Ò×Êܵ½CSRF¹¥»÷ºÍ»ùÓÚ·´ÉäµÄXSS¹¥»÷£¬½áºÏÈý¸ö·ì϶£¬Í¨¹ýÓÕµ¼ÖÎÀíÔ±µã»÷¶ñÒâÁ´½Ó×îÖÕÄܹ»µ¼ÖÂÔ¶³ÌºÅÁîÖ´ÐС£


·ì϶ÑéÖ¤


»ú¹Ø¶ñÒâip²ÎÊý£¬ÊµÏÖÔ¶³ÌºÅÁîÖ´ÐУ¬»ñȡԶ³Ì·þÎñÆ÷µÄpasswdÎļþ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


POC£ºhttps://github.com/aas-n/CVE/tree/master/plainview-activity-monitor

EXP£ºhttps://www.exploit-db.com/exploits/45274/


½¨¸´½¨Òé


Wordpress¹Ù·½ÒѾ­°ä²¼ÁË×îа汾½¨¸´ÁËÉÏÊö·ì϶£¬ÊÜÓ°ÏìµÄÓû§Çëʵʱ¸üнøÐзÀ»¤¡£


ÏÂÔØÁ´½Ó£ºhttps://wordpress.org/plugins/plainview-activity-monitor/


²Î¿¼Á´½Ó


http://seclists.org/bugtraq/2018/Aug/54