WordPress CMS 佨¸´·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-06-27

·ì϶±àºÅºÍ¼¶±ð


CVE-2018-12895  ¸ßΣ  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


¸Ã·ì϶ӰÏìËùÓÐWordPress CMS°æ±¾ £¬Ô̺¬×îа汾v4.9.6¡£


·ì϶¸ÅÊö


ÀûÓô˷ì϶ʹ¹¥»÷Õß¿ÉÄÜɾ³ýWordPress×°ÖõÄÈκÎÎļþ£¨+ PHP·þÎñÆ÷ÉϵÄÈÎºÎÆäËûÎļþ £¬PHP¹ý³ÌÓû§ÓµÓÐÊʵ±µÄɾ³ýȨÏÞ£©¡£ ³ýÁËɾ³ýÕû¸öWordPress×°ÖõĿÉÄÜÐÔ£¨ÈôÊÇûÓе±Ç°±¸·Ý¿ÉÓûᵼÖ¿àÄÑÐÔºó¹û£© £¬¹¥»÷ÕßÄܹ»ÀûÓÃËÁÒâÎļþɾ³ýÖ°ÄÜÈÆ¹ýһЩ°²È«´ëÊ©²¢ÔÚWeb·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£ ¸üÈ·ÇеØËµ £¬Äܹ»É¾³ýÒÔÏÂÎļþ£º


.htaccess£º ͨ³£ £¬É¾³ý´ËÎļþ²»»áÓÐÈκΰ²È«ºó¹û¡£ µ«ÊÇ £¬ÔÚijЩÇé¿öÏ £¬ .htaccess ÎļþÔ̺¬Ó밲ȫÓйصÄÔ¼Êø£¨ÀýÈç £¬¶ÔijЩÎļþ¼ÐµÄ½Ó¼ûÏÞ¶È£©¡£ ɾ³ý´ËÎļþ½«»á½ûÓÃÕâЩ°²È«ÏÞ¶È¡£


index.phpÎļþ£º ͨ³£Çé¿öÏ £¬½«¿ÕµÄ index.php Îļþ¸éÖõ½Ä¿Â¼ÖÐ £¬ÒÔÔ¤·ÀWeb·þÎñÆ÷ÎÞ·¨Ö´ÐеÄÇé¿öϵÄĿ¼Áбí¡£ ɾ³ýÕâЩÎļþ½«Îª¹¥»÷ÕßÌṩһ·ÝÁбí £¬ÁгöÊÜ´Ë´ëÊ©±£»¤µÄĿ¼ÖеÄËùÓÐÎļþ¡£


wp-config.php£º ɾ³ýÕâ¸öWordPress×°ÖÃÎļþ»á±ÉÈ˴νӼû¸ÃÍøÕ¾Ê±´¥·¢WordPress×°Öùý³Ì¡£ ÕâÊÇÓÉÓÚ wp-config.php Ô̺¬Êý¾Ý¿âƾ֤ £¬ÈôÊÇûÓÐËü £¬WordPressµÄÐÐΪ¾ÍÈçͬËüÉÐδװÖᣠ¹¥»÷ÕßÄܹ»É¾³ý¸ÃÎļþ £¬Ê¹ÓÃÖÎÀíÔ¹ØÊ»§Ñ¡ÔñµÄÍ´´¦½øÐÐ×°Öùý³Ì £¬×îºóÔÚ·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£


·ì϶ÑéÖ¤


·ì϶ÑéÖ¤ÊÓÆµ


http://player.youku.com/embed/XMzY4OTIzNDc4NA==


½¨¸´½¨Òé


·ì϶·¢ÏÖÕß £¬°ä²¼ÁËÒ»¸öһʱ½¨²¹²½Ö裺


²Î¿¼https://blog.ripstech.com/2018/wordpress-file-delete-to-code-execution/
Temporary Hotfix

 

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

 

¹¦·òÏß


2017Äê11ÔÂ20ÈÕÔÚHackeroneÉÏÏòWordPress°²È«ÍŶӻ㱨·ì϶¡£
2017Äê11ÔÂ22ÈÕÕâ¸ö·ì϶±»°²È«ÍŶӷÖÀàºÍÑéÖ¤¡£
2017Äê12ÔÂ12ÈÕѯÎʽøÕ¹Çé¿ö¡£
2017Äê12ÔÂ18ÈÕWordpressÔÚ¿ª·¢Ò»¸ö²¹¶¡·¨Ê½¡£ ÒªÇó°ä²¼ÈÕÆÚ¡£ ûÓз´Ó³¡£
2018Äê01ÔÂ09ÈÕÒªÇó°ä²¼ÈÕÆÚ¡£Ã»Óз´Ó³¡£
2018Äê01ÔÂ20ÈÕÓÉÓÚÎÊÌâµÄÑϳÁÐԺͲ»×㹵ͨ £¬±»ÒªÇó¶ÔHackerone½øÐÐÅŽâ¡£
2018Äê01ÔÂ24ÈÕWordPress°²È«ÍŶӹÀ¼Æ±ØÒª6¸öԵŦ·òÄÜÁ¦½¨¸´¡£
2018Äê05ÔÂ24ÈÕѯÎÊÓйØÎÊÌâµÄ½øÕ¹ºÍ/»ò´òËã £¬²¢ÌáÐÑÎÒÃǾ¡¿ì°ä²¼¡£Ã»Óз´Ó³¡£
2018Äê05ÔÂ24ÈÕ½«ÍÆÌØDM·¢Ë͸ø°²È«ÍŶÓ £¬ÒÔÈ·±£ËûÃDz»»áºöÂÔHackeroneÉϵÄÐÂÎÅ¡£
2018Äê06ÔÂ26Èջ㱨ʵÏÖºó7¸öÔÂÒÔÉÏÈÔδ½â¾öÎÊÌâ¡£


²Î¿¼Á´½Ó


https://blog.ripstech.com/2018/wordpress-file-delete-to-code-execution/
https://nvd.nist.gov/vuln/detail/CVE-2018-12895