Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Wordpress WPTouch Authenticated File Upload filter_list
Author
Message
Wordpress WPTouch Authenticated File Upload #1
The Wordpress WPTouch plugin contains an authtenticated file upload vulnerability. A-nonce wp (token CSRF) is created on the backend index page and the same reason is used in handling the file upload through the ajax plugin. By sending the captured nonce with the load, we can upload arbitrary files to the upload folder. Because the plug-in also uses its own file upload mechanism instead of the wordpress API it is possible to upload any type of file. The provided user does not need special rights, and users with a "Contributor" role can be abused.

Version Vulnerable: 3.4.3
Parching: YES

Use:

Code:
msf > use exploit/unix/webapp/wp_wptouch_file_upload       msf exploit(wp_wptouch_file_upload) > show targets             ...targets... msf exploit(wp_wptouch_file_upload) > set TARGET <target-id>       msf exploit(wp_wptouch_file_upload) > show options             ...show and set options... msf exploit(wp_wptouch_file_upload) > exploit

You must have a user and password to start the exploit, you do not need to be an adm can be a normal login, then we will start the
USER set, Set Password, set Rhost and set TARGETURI,

[Image: 1a490678a06cf3cfdf83a9864d6644a7.png]

[Image: 0738e91d7cf1a25d67d0f12bf552500b.png]

Then an upload in meterpreter to upload shell.php

[Image: 7e314d05c0a725fdf9d1435aaa21f2ac.png]

[Image: 0430a382b11486e7d0e9a4fe4d6882ce.png]

I hide url website Tongue
[Image: Vs4P58c.png]

Reply