WordPress Total Donations²å¼þ0day·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-01-29·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-6703£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Total Donations²å¼þ2.0.5¼°Ö®Ç°ËùÓа汾
·ì϶¸ÅÊö
WordPressÊÇWordPressÈí¼þ»ù½ð»áµÄÒ»Ì×ʹÓÃPHP˵»°¿ª·¢µÄ²©¿Íƽ̨£¬£¬£¬£¬£¬¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄ·þÎñÆ÷ÉϼÜÉèÓ×ÎÒ²©¿ÍÍøÕ¾¡£¡£¡£¡£¡£¡£
Total Donations PluginÊÇʹÓÃÔÚÆäÖеÄÒ»¸öÍøÕ¾¾èÔùÖÎÀí²å¼þ£¬£¬£¬£¬£¬Ä¿Ç°ÒѾÉÕ»ÙÊØ»¤¡£¡£¡£¡£¡£¡£
¸Ã²å¼þµÄ´úÂëÔ̺¬¼¸¸öÉè¼ÆÈ±µã£¬£¬£¬£¬£¬ÕâЩȱµã´ÓÕûÌå´ó½«²å¼þºÍWordPressÍøÕ¾Â¶³öÔÚ²»°²È«µÄ»·¾³ÖУ¬£¬£¬£¬£¬²å¼þµÄmigla_ajax_functions.phpÎļþ´æÔÚ½Ó¼û½ÚÔìÃýÎó·ì϶£¬£¬£¬£¬£¬ÈκÎδ¾ÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¶¼Äܹ»²Ù×÷¸Ã²å¼þ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÏòwp-admin/admin-ajax.phpÎļþ·¢ËÍÒªÇóÀûÓø÷ì϶¸üÐÂËÁÒâWordPress Õ¾µãµÄÖ÷ÌâÉèÖÃÏîµÄÊýÖµ£¬£¬£¬£¬£¬¸ü¸Ä²å¼þÓйصÄÉèÖ㬣¬£¬£¬£¬Åú¸Äͨ¹ý²å¼þÊÕµ½µÄ¾è¿îµÄÖ¸±êÕÊ»§£¬£¬£¬£¬£¬ÉõÖÁ¼ìË÷Mailchp ÓʼþÁÐ±í£¬£¬£¬£¬£¬½ø¶ø½ÚÔìÍøÕ¾¡£¡£¡£¡£¡£¡£
×÷Ϊһ¸öóÒײúÆ·£¬£¬£¬£¬£¬¸Ã²å¼þ²»»áÓÐÒ»¸öÖØ´óµÄÓû§Èº¡£¡£¡£¡£¡£¡£µ«¸Ã²å¼þ×îÓпÉÄÜ×°ÖÃÔÚÕ¼ÓдóÁ¿Óû§ÈºµÄ WordPress ÍøÕ¾ÉÏ£¬£¬£¬£¬£¬ÕâÐ©ÍøÕ¾ÊǺڿ͵ÄÖØÒªÖ¸±ê¡£¡£¡£¡£¡£¡£
·ì϶ÀûÓÃ
ÔÝÎÞPOC/EXP.
½¨¸´½¨Ò飺
Ŀǰ³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ©½â¾ö´Ë°²È«ÎÊÌ⣬£¬£¬£¬£¬½¨Òéɾ³ýÕû¸ö²å¼þ¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó£º
https://www.zdnet.com/article/wordpress-sites-under-attack-via-zero-day-in-abandoned-plugin/
https://www.wordfence.com/blog/2019/01/wordpress-sites-compromised-via-zero-day-vulnerabilities-in-total-donations-plugin/


¾©¹«Íø°²±¸11010802024551ºÅ