WordPress²å¼þDuplicator°²È«·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-02-25·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Duplicator 1.3.28֮ǰ°æ±¾
Duplicator Pro 3.8.7.1֮ǰ°æ±¾
·ì϶¸ÅÊö
DuplicatorÊÇÒ»¸öµ¥Ò»µÄ±¸·ÝºÍÕ¾µãǨáãʵÓ÷¨Ê½¡£¡£¡£¡£¡£¡£ËüʹWordPressÍøÕ¾ÖÎÀíÔ±¿ÉÄÜǨá㣬£¬£¬£¬£¬£¬£¬¸´Ô죬£¬£¬£¬£¬£¬£¬Òƶ¯»ò¿ËÂ¡ÍøÕ¾¡£¡£¡£¡£¡£¡£
WordPress°µÊ¾£¬£¬£¬£¬£¬£¬£¬¸ÃÈí¼þÒѾ±»ÏÂÔØ³¬¹ý1500Íò´Î£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ³¬¹ý100Íò¸öÍøÕ¾ÉÏʹÓᣡ£¡£¡£¡£¡£
ÔÚ°æ±¾1.3.28֮ǰµÄDuplicatorºÍ°æ±¾3.8.7.1֮ǰµÄDuplicator ProÔ̺¬Ò»¸öδ¾Éí·ÝÑéÖ¤µÄËÁÒâÎļþÏÂÔØ·ì϶¡£¡£¡£¡£¡£¡£Î´¾ÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬£¬Í¨¹ýʹÓÃÒ×Êܹ¥»÷µÄDuplicator²å¼þÏòWordPressÍøÕ¾·¢ËÍÌØÔìÒªÇóÀ´ÀûÓô˷ì϶¡£¡£¡£¡£¡£¡£
¹¥»÷ÕßÄܹ»Ê¹ÓÃõè¾¶±é´ÓÀ´½Ó¼ûDuplicatorÖ¸¶¨õè¾¶Ö®±íµÄÎļþ£¬£¬£¬£¬£¬£¬£¬ÕâЩÎļþ¿ÉÄÜÔ̺¬wp-config.phpÎļþ¡£¡£¡£¡£¡£¡£ÕâÊÇWordPressÕ¾µãÅäÖÃÎļþ£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþÔ̺¬Êý¾Ý¿âÍ´´¦¡¢Éí·ÝÑéÖ¤ÃÜÔ¿ºÍÑΡ£¡£¡£¡£¡£¡£Í¨¹ýÕâЩʹ´¦£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÔÊÐíÔ¶³ÌÏνӣ¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Ö±½Ó½Ó¼ûÊܺ¦Õ¾µãµÄÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Ê¹Óô˽ӼûȨÏÞ´´½¨×Ô¼ºµÄÖÎÀíÔ¹ØÊ»§²¢½øÒ»²½·çÏÕÕ¾µã£¬£¬£¬£¬£¬£¬£¬»òÕßÖ»Ðè²åÈëÄÚÈÝ»ò»ñÈ¡Êý¾Ý¼´¿É¡£¡£¡£¡£¡£¡£
×êÑÐÈËÔ±¿´µ½µÄÏÕЩËùÓй¥»÷¶¼À´×Ôͳһ¸öIPµØÖ·£¬£¬£¬£¬£¬£¬£¬Äܹ»Ê¹ÓÃÒÔÏÂIOCÀ´È·¶¨ÄúµÄÕ¾µãÊÇ·ñÊܵ½¹¥»÷£º
IP:77.71.115.52
´øÓÐÒÔϲéÎÊ×Ö·û´®µÄGETÒªÇó£º
action=duplicator_download
file=/../wp-config.php
·ì϶ÑéÖ¤
ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼а汾ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬£¬£¬»ñÈ¡Á´½Ó£ºhttps://wordpress.org/plugins/duplicator/¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://threatpost.com/active-attacks-duplicator-wordpress-plugin/153138/


¾©¹«Íø°²±¸11010802024551ºÅ