WordPress ²å¼þSocial WarfareÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-03-25Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
ÊÜÓ°Ïì²úÆ·£º
²å¼þSocial Warfare v3.5.1ºÍv3.5.2
Îó²î¸ÅÊö
Õâ¸ö´æ´¢¿çÕ¾µã¾ç±¾£¨XSS£©Îó²î±£´æÓÚWordPress²å¼þ¡°Social Warfare¡±ÖУ¬£¬£¬ËüÔÊÐíÔ¶³Ìδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÖ´Ðд洢ÔÚWordPressÍøÕ¾Êý¾Ý¿âÖеÄJavaScript´úÂë¡£¡£¡£
ÔÚÈ·¶¨ÏÖÔÚÓµÓÐÁè¼Ý70,000¶à¸ö×°ÖõÄÒ×Êܹ¥»÷µÄ²å¼þÔÚÒ°Íâ±»Æð¾¢Ê¹ÓÃÖ®ºó£¬£¬£¬¡°Social Warfare¡±±»´ÓWordPress²å¼þ´æ´¢ÖÐɾ³ý£¬£¬£¬²¢ÔÚ¿ª·¢ÍŶÓÐû²¼²¹¶¡ÒÔÐÞ¸´ºóÔÙÌí¼Ó»ØÀ´¡£¡£¡£ÏÂͼÀ´×ÔWordPress²å¼þ´æ´¢¿âµÄ²å¼þ¡°Social Warfare¡±µÄÏÂÔØÀúÊ·ÐÅÏ¢ÏÔʾµ±Ìì¼Í¼µÄÏÂÔØÁ¿Ô¼ÄªÎª19K£¬£¬£¬µ«ÈÔÓÐÏ൱¶àµÄÍøÕ¾ÈÔʹÓÃÒ×Êܹ¥»÷µÄSocial Warfare°æ±¾¡£¡£¡£
Äú¿ÉÒÔÔÚ»á¼ûÈÕÖ¾ÖвéÕÒÖ¸ÏòÈκÎPHPÎļþ/ wp-admin /µÄÇëÇóÒÔ¼°ÒÔϲÎÊý£º
swp_debug
swp_url
Ñо¿Ö°Ô±ÔÚÒ»°Ù¶àÖÖ²î±ðµÄIPÖп´µ½ÁË´ó×ÚµÄÎó²îʹÓÃʵÑé¡£¡£¡£
¹¥»÷Õßͨ¹ý¼ÓÔØÒÔÏÂURL https://pastebin.com/raw/0yJzqbYf×¢Èë¶ñÒâjavascript¾ç±¾£¬£¬£¬ÆäÖаüÀ¨´Ë¶ñÒâ¸ºÔØ£º
´Ë¾ç±¾½«Óû§Öض¨Ïòµ½ÁíÒ»¸ö¶ñÒâÕ¾µã¡£¡£¡£
ÐÞ¸´½¨Òé
½¨ÒéËùÓÐʹÓá°Social Warfare¡±²å¼þµÄÕ¾µã¸üÐÂÖÁ×îа汾 v3.5.3£ºhttps://wordpress.org/support/topic/malware-into-new-update/#post-11341492¡£¡£¡£
²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/zero-day-wordpress-plugin-vulnerability-used-to-add-malicious-redirects/
https://blog.sucuri.net/2019/03/zero-day-stored-xss-in-social-warfare.html?
utm_source=Twitter&utm_medium=Social&utm_campaign=Blog&utm_term=EN&utm_content=zero-day-stored-xss-in-social-warfare