WordPress Ad Inserter²å¼þÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-17

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.9£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

ÊÊÓÃÓÚWordPress Ad Inserter²å¼þ<= 2.4.21¡£¡£¡£¡£¡£


Îó²î¸ÅÊö


WordPressÊÇWordPress»ù½ð»áµÄÒ»Ì×ʹÓÃPHPÓïÑÔ¿ª·¢µÄ²©¿Íƽ̨¡£¡£¡£¡£¡£¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄЧÀÍÆ÷ÉϼÜÉèСÎÒ˽¼Ò²©¿ÍÍøÕ¾¡£¡£¡£¡£¡£Ad InserterÊÇÒ»¿îÕë¶ÔWordpressµÄ¹ã¸æ²å¼þ£¬£¬£¬£¬£¬¾ß±¸Ðí¶à¸ß¼¶µÄ¹ã¸æÖÎÀí¹¦Ð§£¬£¬£¬£¬£¬×ÊÖúÎÒÃÇÔÚWordpressÍøÕ¾í§ÒâλÖòåÈëͶ·Å¹ã¸æ´úÂëºÍͶ·ÅÏÔʾ¹ã¸æ¡£¡£¡£¡£¡£²¢ÇÒ¿ÉÒÔÖ§³ÖÖÖÖÖ¹ã¸æ£¬£¬£¬£¬£¬°üÀ¨Google AdSense¹ã¸æ£¬£¬£¬£¬£¬ÄÚÈÝÏà¹ØµÄÑÇÂíÑ·Ô­Éú¹ºÎï¹ã¸æ£¬£¬£¬£¬£¬Media.net¹ã¸æºÍÂÖ²¥ºá·ù¹ã¸æµÈ¡£¡£¡£¡£¡£


¸ÃÎó²îÔ´ÓÚʹÓÃcheck_admin_referer£¨£©¾ÙÐÐÊÚȨ£¬£¬£¬£¬£¬ËüÊÇרÃÅÓÃÓÚ±£»£»£» £»£»£»¤WordPressÕ¾µãÃâÊÜʹÓÃnonceµÄ¿çÕ¾µãÇëÇóαÔ죨CSRF£©¹¥»÷¡£¡£¡£¡£¡£Ò»µ©¹¥»÷ÕßÓµÓÐÒ»¸önonce¿É¹©ËûʹÓ㬣¬£¬£¬£¬Ëû¾Í¿ÉÒÔÁ¬Ã¦´¥·¢µ÷ÊÔ¹¦Ð§£¬£¬£¬£¬£¬ÉõÖÁͨ¹ý·¢ËͰüÀ¨í§ÒâPHP´úÂëµÄ¶ñÒâ¸ºÔØÀ´Ê¹ÓÃ¹ã¸æÔ¤ÀÀ¹¦Ð§¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://wordpress.org/plugins/ad-inserter/#developers¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


 https://www.bleepingcomputer.com/news/security/critical-bug-in-wordpress-plugin-lets-hackers-execute-code/