WordPress ²å¼þSocial WarfareÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-03-25

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


ÊÜÓ°Ïì²úÆ·£º

²å¼þSocial Warfare v3.5.1ºÍv3.5.2


Îó²î¸ÅÊö


Õâ¸ö´æ´¢¿çÕ¾µã¾ç±¾£¨XSS£©Îó²î±£´æÓÚWordPress²å¼þ¡°Social Warfare¡±ÖУ¬£¬£¬ËüÔÊÐíÔ¶³Ìδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÖ´Ðд洢ÔÚWordPressÍøÕ¾Êý¾Ý¿âÖеÄJavaScript´úÂë¡£¡£¡£


ÔÚÈ·¶¨ÏÖÔÚÓµÓÐÁè¼Ý70,000¶à¸ö×°ÖõÄÒ×Êܹ¥»÷µÄ²å¼þÔÚÒ°Íâ±»Æð¾¢Ê¹ÓÃÖ®ºó£¬£¬£¬¡°Social Warfare¡±±»´ÓWordPress²å¼þ´æ´¢ÖÐɾ³ý£¬£¬£¬²¢ÔÚ¿ª·¢ÍŶÓÐû²¼²¹¶¡ÒÔÐÞ¸´ºóÔÙÌí¼Ó»ØÀ´¡£¡£¡£ÏÂͼÀ´×ÔWordPress²å¼þ´æ´¢¿âµÄ²å¼þ¡°Social Warfare¡±µÄÏÂÔØÀúÊ·ÐÅÏ¢ÏÔʾµ±Ìì¼Í¼µÄÏÂÔØÁ¿Ô¼ÄªÎª19K£¬£¬£¬µ«ÈÔÓÐÏ൱¶àµÄÍøÕ¾ÈÔʹÓÃÒ×Êܹ¥»÷µÄSocial Warfare°æ±¾¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Äú¿ÉÒÔÔÚ»á¼ûÈÕÖ¾ÖвéÕÒÖ¸ÏòÈκÎPHPÎļþ/ wp-admin /µÄÇëÇóÒÔ¼°ÒÔϲÎÊý£º

swp_debug

swp_url

Ñо¿Ö°Ô±ÔÚÒ»°Ù¶àÖÖ²î±ðµÄIPÖп´µ½ÁË´ó×ÚµÄÎó²îʹÓÃʵÑé¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¹¥»÷Õßͨ¹ý¼ÓÔØÒÔÏÂURL https://pastebin.com/raw/0yJzqbYf×¢Èë¶ñÒâjavascript¾ç±¾£¬£¬£¬ÆäÖаüÀ¨´Ë¶ñÒâ¸ºÔØ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


´Ë¾ç±¾½«Óû§Öض¨Ïòµ½ÁíÒ»¸ö¶ñÒâÕ¾µã¡£¡£¡£


ÐÞ¸´½¨Òé


½¨ÒéËùÓÐʹÓá°Social Warfare¡±²å¼þµÄÕ¾µã¸üÐÂÖÁ×îа汾 v3.5.3£ºhttps://wordpress.org/support/topic/malware-into-new-update/#post-11341492¡£¡£¡£


²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/security/zero-day-wordpress-plugin-vulnerability-used-to-add-malicious-redirects/


https://blog.sucuri.net/2019/03/zero-day-stored-xss-in-social-warfare.html?


utm_source=Twitter&utm_medium=Social&utm_campaign=Blog&utm_term=EN&utm_content=zero-day-stored-xss-in-social-warfare