WordPress Ad Inserter²å¼þÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-07-17

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.9£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

ºÏÓÃÓÚWordPress Ad Inserter²å¼þ<= 2.4.21¡£


·ì϶¸ÅÊö


WordPressÊÇWordPress»ù½ð»áµÄÒ»Ì×ʹÓÃPHP˵»°¿ª·¢µÄ²©¿Íƽ̨¡£¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄ·þÎñÆ÷ÉϼÜÉèÓ×ÎÒ²©¿ÍÍøÕ¾¡£Ad InserterÊÇÒ»¿îÕë¶ÔWordpressµÄ¸æ°×²å¼þ£¬¾ß±¸ºÃ¶à¸ß¼¶µÄ¸æ°×ÖÎÀíÖ°ÄÜ£¬Ô®ÊÖÎÒÃÇÔÚWordpressÍøÕ¾ËÁÒâµØÎ»²åÈëͶ·Å¸æ°×´úÂëºÍͶ·ÅÏÔʾ¸æ°×¡£²¢ÇÒÄܹ»Ö§³Ö¸÷Àà¸æ°×£¬Ô̺¬Google AdSense¸æ°×£¬ÄÚÈÝÓйصÄÑÇÂíÑ·Ô­Éú¹ºÎï¸æ°×£¬Media.net¸æ°×ºÍÂÖ²¥ºá·ù¸æ°×µÈ¡£


¸Ã·ì϶ԴÓÚʹÓÃcheck_admin_referer£¨£©½øÐÐÊÚȨ£¬ËüÊÇרÃÅÓÃÓÚ±£»¤WordPressÕ¾µãÃâÊÜʹÓÃnonceµÄ¿çÕ¾µãÒªÇóαÔ죨CSRF£©¹¥»÷¡£Ò»µ©¹¥»÷ÕßÕ¼ÓÐÒ»¸önonce¿É¹©ËûʹÓã¬Ëû¾ÍÄܹ»µ±¼´´¥·¢µ÷ÊÔÖ°ÄÜ£¬ÉõÖÁͨ¹ý·¢ËÍÔ̺¬ËÁÒâPHP´úÂëµÄ¶ñÒâ¸ºÔØÀ´ÀûÓøæ°×Ô¤ÀÀÖ°ÄÜ¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://wordpress.org/plugins/ad-inserter/#developers¡£


²Î¿¼Á´½Ó


 https://www.bleepingcomputer.com/news/security/critical-bug-in-wordpress-plugin-lets-hackers-execute-code/