WordPress PAM²å¼þÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-08-30Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-15877£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Plainview Activity Monitor plugin version <= 20161228
Îó²î¸ÅÊö
WordPress ²å¼þPlainview Activity Monitor±»ÆØ³ö±£´æÒ»¸öÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£Plainview Activity Monitor ÊÇÒ»¿îÍøÕ¾Óû§»î¶¯¼à¿Ø²å¼þ¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòurl¡°/wp-admin/admin.php?page=plainview_activity_monitor&tab=activity_tools¡±·¢ËÍÈ«ÐĽṹµÄ¡°ip¡±²ÎÊýÀ´Ê¹ÓøÃÎó²î¡£¡£¡£¡£¡£¡£´ËÎó²îµÄÀÖ³ÉʹÓÃÐèÒªÌØÈ¨£¬£¬£¬£¬£¬¿ÉÊÇ´æÓиÃÎó²îµÄ²å¼þ°æ±¾Ò²Ò×Êܵ½CSRF¹¥»÷ºÍ»ùÓÚ·´ÉäµÄXSS¹¥»÷£¬£¬£¬£¬£¬Á¬ÏµÈý¸öÎó²î£¬£¬£¬£¬£¬Í¨¹ýÓÕµ¼ÖÎÀíÔ±µã»÷¶ñÒâÁ´½Ó×îÖÕ¿ÉÒÔµ¼ÖÂÔ¶³ÌÏÂÁîÖ´ÐС£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
½á¹¹¶ñÒâip²ÎÊý£¬£¬£¬£¬£¬ÊµÏÖÔ¶³ÌÏÂÁîÖ´ÐУ¬£¬£¬£¬£¬»ñȡԶ³ÌЧÀÍÆ÷µÄpasswdÎļþ
POC£ºhttps://github.com/aas-n/CVE/tree/master/plainview-activity-monitor
EXP£ºhttps://www.exploit-db.com/exploits/45274/
ÐÞ¸´½¨Òé
Wordpress¹Ù·½ÒѾÐû²¼ÁË×îа汾ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÓû§Çëʵʱ¸üоÙÐзÀ»¤¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://wordpress.org/plugins/plainview-activity-monitor/
²Î¿¼Á´½Ó