WordPress CMS 佨¸´·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-06-27

·ì϶±àºÅºÍ¼¶±ð


CVE-2018-12895  ¸ßΣ  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


¸Ã·ì϶ӰÏìËùÓÐWordPress CMS°æ±¾£¬ £¬£¬£¬£¬£¬ £¬£¬Ô̺¬×îа汾v4.9.6¡£¡£¡£¡£¡£¡£¡£


·ì϶¸ÅÊö


ÀûÓô˷ì϶ʹ¹¥»÷Õß¿ÉÄÜɾ³ýWordPress×°ÖõÄÈκÎÎļþ£¨+ PHP·þÎñÆ÷ÉϵÄÈÎºÎÆäËûÎļþ£¬ £¬£¬£¬£¬£¬ £¬£¬PHP¹ý³ÌÓû§ÓµÓÐÊʵ±µÄɾ³ýȨÏÞ£©¡£¡£¡£¡£¡£¡£¡£ ³ýÁËɾ³ýÕû¸öWordPress×°ÖõĿÉÄÜÐÔ£¨ÈôÊÇûÓе±Ç°±¸·Ý¿ÉÓûᵼÖ¿àÄÑÐÔºó¹û£©£¬ £¬£¬£¬£¬£¬ £¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃËÁÒâÎļþɾ³ýÖ°ÄÜÈÆ¹ýһЩ°²È«´ëÊ©²¢ÔÚWeb·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£ ¸üÈ·ÇеØËµ£¬ £¬£¬£¬£¬£¬ £¬£¬Äܹ»É¾³ýÒÔÏÂÎļþ£º


.htaccess£º ͨ³££¬ £¬£¬£¬£¬£¬ £¬£¬É¾³ý´ËÎļþ²»»áÓÐÈκΰ²È«ºó¹û¡£¡£¡£¡£¡£¡£¡£ µ«ÊÇ£¬ £¬£¬£¬£¬£¬ £¬£¬ÔÚijЩÇé¿öÏ£¬ £¬£¬£¬£¬£¬ £¬£¬ .htaccess ÎļþÔ̺¬Ó밲ȫÓйصÄÔ¼Êø£¨ÀýÈ磬 £¬£¬£¬£¬£¬ £¬£¬¶ÔijЩÎļþ¼ÐµÄ½Ó¼ûÏÞ¶È£©¡£¡£¡£¡£¡£¡£¡£ ɾ³ý´ËÎļþ½«»á½ûÓÃÕâЩ°²È«ÏÞ¶È¡£¡£¡£¡£¡£¡£¡£


index.phpÎļþ£º ͨ³£Çé¿öÏ£¬ £¬£¬£¬£¬£¬ £¬£¬½«¿ÕµÄ index.php Îļþ¸éÖõ½Ä¿Â¼ÖУ¬ £¬£¬£¬£¬£¬ £¬£¬ÒÔÔ¤·ÀWeb·þÎñÆ÷ÎÞ·¨Ö´ÐеÄÇé¿öϵÄĿ¼ÁÐ±í¡£¡£¡£¡£¡£¡£¡£ ɾ³ýÕâЩÎļþ½«Îª¹¥»÷ÕßÌṩһ·ÝÁÐ±í£¬ £¬£¬£¬£¬£¬ £¬£¬ÁгöÊÜ´Ë´ëÊ©±£»£»£»£»£»£»£»£»¤µÄĿ¼ÖеÄËùÓÐÎļþ¡£¡£¡£¡£¡£¡£¡£


wp-config.php£º ɾ³ýÕâ¸öWordPress×°ÖÃÎļþ»á±ÉÈ˴νӼû¸ÃÍøÕ¾Ê±´¥·¢WordPress×°Öùý³Ì¡£¡£¡£¡£¡£¡£¡£ ÕâÊÇÓÉÓÚ wp-config.php Ô̺¬Êý¾Ý¿âƾ֤£¬ £¬£¬£¬£¬£¬ £¬£¬ÈôÊÇûÓÐËü£¬ £¬£¬£¬£¬£¬ £¬£¬WordPressµÄÐÐΪ¾ÍÈçͬËüÉÐδװÖᣡ£¡£¡£¡£¡£¡£ ¹¥»÷ÕßÄܹ»É¾³ý¸ÃÎļþ£¬ £¬£¬£¬£¬£¬ £¬£¬Ê¹ÓÃÖÎÀíÔ¹ØÊ»§Ñ¡ÔñµÄÍ´´¦½øÐÐ×°Öùý³Ì£¬ £¬£¬£¬£¬£¬ £¬£¬×îºóÔÚ·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


·ì϶ÑéÖ¤ÊÓÆµ


http://player.youku.com/embed/XMzY4OTIzNDc4NA==


½¨¸´½¨Òé


·ì϶·¢ÏÖÕߣ¬ £¬£¬£¬£¬£¬ £¬£¬°ä²¼ÁËÒ»¸öһʱ½¨²¹²½Ö裺


²Î¿¼https://blog.ripstech.com/2018/wordpress-file-delete-to-code-execution/
Temporary Hotfix

 

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

 

¹¦·òÏß


2017Äê11ÔÂ20ÈÕÔÚHackeroneÉÏÏòWordPress°²È«ÍŶӻ㱨·ì϶¡£¡£¡£¡£¡£¡£¡£
2017Äê11ÔÂ22ÈÕÕâ¸ö·ì϶±»°²È«ÍŶӷÖÀàºÍÑéÖ¤¡£¡£¡£¡£¡£¡£¡£
2017Äê12ÔÂ12ÈÕѯÎʽøÕ¹Çé¿ö¡£¡£¡£¡£¡£¡£¡£
2017Äê12ÔÂ18ÈÕWordpressÔÚ¿ª·¢Ò»¸ö²¹¶¡·¨Ê½¡£¡£¡£¡£¡£¡£¡£ ÒªÇó°ä²¼ÈÕÆÚ¡£¡£¡£¡£¡£¡£¡£ ûÓз´Ó³¡£¡£¡£¡£¡£¡£¡£
2018Äê01ÔÂ09ÈÕÒªÇó°ä²¼ÈÕÆÚ¡£¡£¡£¡£¡£¡£¡£Ã»Óз´Ó³¡£¡£¡£¡£¡£¡£¡£
2018Äê01ÔÂ20ÈÕÓÉÓÚÎÊÌâµÄÑϳÁÐԺͲ»×㹵ͨ£¬ £¬£¬£¬£¬£¬ £¬£¬±»ÒªÇó¶ÔHackerone½øÐÐÅŽ⡣¡£¡£¡£¡£¡£¡£
2018Äê01ÔÂ24ÈÕWordPress°²È«ÍŶӹÀ¼Æ±ØÒª6¸öԵŦ·òÄÜÁ¦½¨¸´¡£¡£¡£¡£¡£¡£¡£
2018Äê05ÔÂ24ÈÕѯÎÊÓйØÎÊÌâµÄ½øÕ¹ºÍ/»ò´òË㣬 £¬£¬£¬£¬£¬ £¬£¬²¢ÌáÐÑÎÒÃǾ¡¿ì°ä²¼¡£¡£¡£¡£¡£¡£¡£Ã»Óз´Ó³¡£¡£¡£¡£¡£¡£¡£
2018Äê05ÔÂ24ÈÕ½«ÍÆÌØDM·¢Ë͸ø°²È«ÍŶӣ¬ £¬£¬£¬£¬£¬ £¬£¬ÒÔÈ·±£ËûÃDz»»áºöÂÔHackeroneÉϵÄÐÂÎÅ¡£¡£¡£¡£¡£¡£¡£
2018Äê06ÔÂ26Èջ㱨ʵÏÖºó7¸öÔÂÒÔÉÏÈÔδ½â¾öÎÊÌâ¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://blog.ripstech.com/2018/wordpress-file-delete-to-code-execution/
https://nvd.nist.gov/vuln/detail/CVE-2018-12895