WordPress Total Donations²å¼þ0dayÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-01-29Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-6703£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Total Donations²å¼þ2.0.5¼°Ö®Ç°ËùÓа汾
Îó²î¸ÅÊö
WordPressÊÇWordPressÈí¼þ»ù½ð»áµÄÒ»Ì×ʹÓÃPHPÓïÑÔ¿ª·¢µÄ²©¿Íƽ̨£¬£¬£¬£¬£¬£¬£¬¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄЧÀÍÆ÷ÉϼÜÉèСÎÒ˽¼Ò²©¿ÍÍøÕ¾¡£¡£¡£
Total Donations PluginÊÇʹÓÃÔÚÆäÖеÄÒ»¸öÍøÕ¾¾èÔùÖÎÀí²å¼þ£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÒѾ·ÅÆúά»¤¡£¡£¡£
¸Ã²å¼þµÄ´úÂë°üÀ¨¼¸¸öÉè¼ÆÈ±ÏÝ£¬£¬£¬£¬£¬£¬£¬ÕâЩȱÏÝ´ÓÕûÌåÉϽ«²å¼þºÍWordPressÍøÕ¾Ì»Â¶ÔÚ²»Çå¾²µÄÇéÐÎÖУ¬£¬£¬£¬£¬£¬£¬²å¼þµÄmigla_ajax_functions.phpÎļþ±£´æ»á¼û¿ØÖƹýʧÎó²î£¬£¬£¬£¬£¬£¬£¬ÈκÎδÂÄÀúÖ¤µÄÔ¶³Ì¹¥»÷Õß¶¼¿ÉÒÔ²Ù×÷¸Ã²å¼þ¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÏòwp-admin/admin-ajax.phpÎļþ·¢ËÍÇëÇóʹÓøÃÎó²î¸üÐÂí§ÒâWordPress Õ¾µãµÄ½¹µãÉèÖÃÏîµÄÊýÖµ£¬£¬£¬£¬£¬£¬£¬¸ü¸Ä²å¼þÏà¹ØµÄÉèÖ㬣¬£¬£¬£¬£¬£¬ÐÞ¸Äͨ¹ý²å¼þÊÕµ½µÄ¾èÇ®µÄÄ¿µÄÕÊ»§£¬£¬£¬£¬£¬£¬£¬ÉõÖÁ¼ìË÷Mailchp ÓʼþÁÐ±í£¬£¬£¬£¬£¬£¬£¬½ø¶ø¿ØÖÆÍøÕ¾¡£¡£¡£
×÷Ϊһ¸öÉÌÒµ²úÆ·£¬£¬£¬£¬£¬£¬£¬¸Ã²å¼þ²»»áÓÐÒ»¸öÖØ´óµÄÓû§Èº¡£¡£¡£µ«¸Ã²å¼þ×îÓпÉÄÜ×°ÖÃÔÚÓµÓдó×ÚÓû§ÈºµÄ WordPress ÍøÕ¾ÉÏ£¬£¬£¬£¬£¬£¬£¬ÕâÐ©ÍøÕ¾ÊǺڿ͵ÄÖ÷ҪĿµÄ¡£¡£¡£
Îó²îʹÓÃ
ÔÝÎÞPOC/EXP.
ÐÞ¸´½¨Ò飺
ÏÖÔÚ³§ÉÌÔÝδÐû²¼ÐÞ¸´²½·¥½â¾ö´ËÇå¾²ÎÊÌ⣬£¬£¬£¬£¬£¬£¬½¨Òéɾ³ýÕû¸ö²å¼þ¡£¡£¡£
²Î¿¼Á´½Ó£º
https://www.zdnet.com/article/wordpress-sites-under-attack-via-zero-day-in-abandoned-plugin/
https://www.wordfence.com/blog/2019/01/wordpress-sites-compromised-via-zero-day-vulnerabilities-in-total-donations-plugin/