WordPress Ad Inserter²å¼þÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-07-17·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.9£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ºÏÓÃÓÚWordPress Ad Inserter²å¼þ<= 2.4.21¡£
·ì϶¸ÅÊö
WordPressÊÇWordPress»ù½ð»áµÄÒ»Ì×ʹÓÃPHP˵»°¿ª·¢µÄ²©¿Íƽ̨¡£¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄ·þÎñÆ÷ÉϼÜÉèÓ×ÎÒ²©¿ÍÍøÕ¾¡£Ad InserterÊÇÒ»¿îÕë¶ÔWordpressµÄ¸æ°×²å¼þ£¬¾ß±¸ºÃ¶à¸ß¼¶µÄ¸æ°×ÖÎÀíÖ°ÄÜ£¬Ô®ÊÖÎÒÃÇÔÚWordpressÍøÕ¾ËÁÒâµØÎ»²åÈëͶ·Å¸æ°×´úÂëºÍͶ·ÅÏÔʾ¸æ°×¡£²¢ÇÒÄܹ»Ö§³Ö¸÷Àà¸æ°×£¬Ô̺¬Google AdSense¸æ°×£¬ÄÚÈÝÓйصÄÑÇÂíÑ·ÔÉú¹ºÎï¸æ°×£¬Media.net¸æ°×ºÍÂÖ²¥ºá·ù¸æ°×µÈ¡£
¸Ã·ì϶ԴÓÚʹÓÃcheck_admin_referer£¨£©½øÐÐÊÚȨ£¬ËüÊÇרÃÅÓÃÓÚ±£»¤WordPressÕ¾µãÃâÊÜʹÓÃnonceµÄ¿çÕ¾µãÒªÇóαÔ죨CSRF£©¹¥»÷¡£Ò»µ©¹¥»÷ÕßÕ¼ÓÐÒ»¸önonce¿É¹©ËûʹÓã¬Ëû¾ÍÄܹ»µ±¼´´¥·¢µ÷ÊÔÖ°ÄÜ£¬ÉõÖÁͨ¹ý·¢ËÍÔ̺¬ËÁÒâPHP´úÂëµÄ¶ñÒâ¸ºÔØÀ´ÀûÓøæ°×Ô¤ÀÀÖ°ÄÜ¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
https://wordpress.org/plugins/ad-inserter/#developers¡£
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ