WordPress Ad Inserter²å¼þÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-17

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.9£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

ÊÊÓÃÓÚWordPress Ad Inserter²å¼þ<= 2.4.21¡£


Îó²î¸ÅÊö


WordPressÊÇWordPress»ù½ð»áµÄÒ»Ì×ʹÓÃPHPÓïÑÔ¿ª·¢µÄ²©¿Íƽ̨¡£¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄ·þÎñÆ÷ÉϼÜÉèСÎÒ˽¼Ò²©¿ÍÍøÕ¾¡£Ad InserterÊÇÒ»¿îÕë¶ÔWordpressµÄ¹ã¸æ²å¼þ£¬¾ß±¸Ðí¶à¸ß¼¶µÄ¹ã¸æÖÎÀí¹¦Ð§£¬×ÊÖúÎÒÃÇÔÚWordpressÍøÕ¾í§ÒâλÖòåÈëͶ·Å¹ã¸æ´úÂëºÍͶ·ÅÏÔʾ¹ã¸æ¡£²¢ÇÒ¿ÉÒÔÖ§³ÖÖÖÖÖ¹ã¸æ£¬°üÀ¨Google AdSense¹ã¸æ£¬ÄÚÈÝÏà¹ØµÄÑÇÂíÑ·Ô­Éú¹ºÎï¹ã¸æ£¬Media.net¹ã¸æºÍÂÖ²¥ºá·ù¹ã¸æµÈ¡£


¸ÃÎó²îÔ´ÓÚʹÓÃcheck_admin_referer£¨£©¾ÙÐÐÊÚȨ£¬ËüÊÇרÃÅÓÃÓÚ±£»¤WordPressÕ¾µãÃâÊÜʹÓÃnonceµÄ¿çÕ¾µãÇëÇóαÔ죨CSRF£©¹¥»÷¡£Ò»µ©¹¥»÷ÕßÓµÓÐÒ»¸önonce¿É¹©ËûʹÓã¬Ëû¾Í¿ÉÒÔÁ¬Ã¦´¥·¢µ÷ÊÔ¹¦Ð§£¬ÉõÖÁͨ¹ý·¢ËͰüÀ¨í§ÒâPHP´úÂëµÄ¶ñÒâ¸ºÔØÀ´Ê¹ÓÃ¹ã¸æÔ¤ÀÀ¹¦Ð§¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://wordpress.org/plugins/ad-inserter/#developers¡£


²Î¿¼Á´½Ó


 https://www.bleepingcomputer.com/news/security/critical-bug-in-wordpress-plugin-lets-hackers-execute-code/