WordPress²å¼þDuplicator°²È«·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-02-25

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Duplicator 1.3.28֮ǰ°æ±¾

Duplicator Pro 3.8.7.1֮ǰ°æ±¾


·ì϶¸ÅÊö


DuplicatorÊÇÒ»¸öµ¥Ò»µÄ±¸·ÝºÍÕ¾µãǨáãʵÓ÷¨Ê½¡£¡£¡£¡£¡£¡£ËüʹWordPressÍøÕ¾ÖÎÀíÔ±¿ÉÄÜǨá㣬£¬£¬£¬£¬£¬£¬¸´Ô죬£¬£¬£¬£¬£¬£¬Òƶ¯»ò¿ËÂ¡ÍøÕ¾¡£¡£¡£¡£¡£¡£


WordPress°µÊ¾£¬£¬£¬£¬£¬£¬£¬¸ÃÈí¼þÒѾ­±»ÏÂÔØ³¬¹ý1500Íò´Î£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ³¬¹ý100Íò¸öÍøÕ¾ÉÏʹÓᣡ£¡£¡£¡£¡£


ÔÚ°æ±¾1.3.28֮ǰµÄDuplicatorºÍ°æ±¾3.8.7.1֮ǰµÄDuplicator ProÔ̺¬Ò»¸öδ¾­Éí·ÝÑéÖ¤µÄËÁÒâÎļþÏÂÔØ·ì϶¡£¡£¡£¡£¡£¡£Î´¾­ÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬£¬Í¨¹ýʹÓÃÒ×Êܹ¥»÷µÄDuplicator²å¼þÏòWordPressÍøÕ¾·¢ËÍÌØÔìÒªÇóÀ´ÀûÓô˷ì϶¡£¡£¡£¡£¡£¡£


¹¥»÷ÕßÄܹ»Ê¹ÓÃõè¾¶±é´ÓÀ´½Ó¼ûDuplicatorÖ¸¶¨õè¾¶Ö®±íµÄÎļþ£¬£¬£¬£¬£¬£¬£¬ÕâЩÎļþ¿ÉÄÜÔ̺¬wp-config.phpÎļþ¡£¡£¡£¡£¡£¡£ÕâÊÇWordPressÕ¾µãÅäÖÃÎļþ£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþÔ̺¬Êý¾Ý¿âÍ´´¦¡¢Éí·ÝÑéÖ¤ÃÜÔ¿ºÍÑΡ£¡£¡£¡£¡£¡£Í¨¹ýÕâЩʹ´¦£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÔÊÐíÔ¶³ÌÏνÓ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Ö±½Ó½Ó¼ûÊܺ¦Õ¾µãµÄÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Ê¹Óô˽ӼûȨÏÞ´´½¨×Ô¼ºµÄÖÎÀíÔ¹ØÊ»§²¢½øÒ»²½·çÏÕÕ¾µã£¬£¬£¬£¬£¬£¬£¬»òÕßÖ»Ðè²åÈëÄÚÈÝ»ò»ñÈ¡Êý¾Ý¼´¿É¡£¡£¡£¡£¡£¡£


×êÑÐÈËÔ±¿´µ½µÄÏÕЩËùÓй¥»÷¶¼À´×Ôͳһ¸öIPµØÖ·£¬£¬£¬£¬£¬£¬£¬Äܹ»Ê¹ÓÃÒÔÏÂIOCÀ´È·¶¨ÄúµÄÕ¾µãÊÇ·ñÊܵ½¹¥»÷£º


IP:77.71.115.52


´øÓÐÒÔϲéÎÊ×Ö·û´®µÄGETÒªÇó£º

action=duplicator_download

file=/../wp-config.php


·ì϶ÑéÖ¤


ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼а汾ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬£¬£¬»ñÈ¡Á´½Ó£ºhttps://wordpress.org/plugins/duplicator/¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://threatpost.com/active-attacks-duplicator-wordpress-plugin/153138/