WordPress²å¼þDuplicatorÇå¾²Îó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-02-25Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Duplicator 1.3.28֮ǰ°æ±¾
Duplicator Pro 3.8.7.1֮ǰ°æ±¾
Îó²î¸ÅÊö
DuplicatorÊÇÒ»¸ö¼òÆÓµÄ±¸·ÝºÍÕ¾µãǨáãÊÊÓóÌÐò¡£¡£¡£ËüʹWordPressÍøÕ¾ÖÎÀíÔ±Äܹ»Ç¨á㣬£¬£¬£¬£¬¸´ÖÆ£¬£¬£¬£¬£¬Òƶ¯»ò¿ËÂ¡ÍøÕ¾¡£¡£¡£
WordPressÌåÏÖ£¬£¬£¬£¬£¬¸ÃÈí¼þÒѾ±»ÏÂÔØÁè¼Ý1500Íò´Î£¬£¬£¬£¬£¬²¢ÔÚÁè¼Ý100Íò¸öÍøÕ¾ÉÏʹÓᣡ£¡£
ÔÚ°æ±¾1.3.28֮ǰµÄDuplicatorºÍ°æ±¾3.8.7.1֮ǰµÄDuplicator Pro°üÀ¨Ò»¸öδ¾Éí·ÝÑéÖ¤µÄí§ÒâÎļþÏÂÔØÎó²î¡£¡£¡£Î´ÂÄÀúÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î£¬£¬£¬£¬£¬Í¨¹ýʹÓÃÒ×Êܹ¥»÷µÄDuplicator²å¼þÏòWordPressÍøÕ¾·¢ËÍÌØÖÆÇëÇóÀ´Ê¹ÓôËÎó²î¡£¡£¡£
¹¥»÷Õß¿ÉÒÔʹÓ÷¾¶±éÏòÀ´»á¼ûDuplicatorÖ¸¶¨Â·¾¶Ö®ÍâµÄÎļþ£¬£¬£¬£¬£¬ÕâЩÎļþ¿ÉÄܰüÀ¨wp-config.phpÎļþ¡£¡£¡£ÕâÊÇWordPressÕ¾µãÉèÖÃÎļþ£¬£¬£¬£¬£¬¸ÃÎļþ°üÀ¨Êý¾Ý¿âƾ֤¡¢Éí·ÝÑéÖ¤ÃÜÔ¿ºÍÑΡ£¡£¡£Í¨¹ýÕâЩƾ֤£¬£¬£¬£¬£¬ÈôÊÇÔÊÐíÔ¶³ÌÅþÁ¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÖ±½Ó»á¼ûÊܺ¦Õ¾µãµÄÊý¾Ý¿â¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓô˻á¼ûȨÏÞ½¨Éè×Ô¼ºµÄÖÎÀíÔ±ÕÊ»§²¢½øÒ»²½Î£º¦Õ¾µã£¬£¬£¬£¬£¬»òÕßÖ»Ðè²åÈëÄÚÈÝ»ò»ñÈ¡Êý¾Ý¼´¿É¡£¡£¡£
Ñо¿Ö°Ô±¿´µ½µÄÏÕЩËùÓй¥»÷¶¼À´×Ôͳһ¸öIPµØµã£¬£¬£¬£¬£¬¿ÉÒÔʹÓÃÒÔÏÂIOCÀ´È·¶¨ÄúµÄÕ¾µãÊÇ·ñÊܵ½¹¥»÷£º
IP:77.71.115.52
´øÓÐÒÔÏÂÅÌÎÊ×Ö·û´®µÄGETÇëÇó£º
action=duplicator_download
file=/../wp-config.php
Îó²îÑéÖ¤
ÔÝÎÞPoC/EXP¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Ð°汾ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬»ñÈ¡Á´½Ó£ºhttps://wordpress.org/plugins/duplicator/¡£¡£¡£
²Î¿¼Á´½Ó
https://threatpost.com/active-attacks-duplicator-wordpress-plugin/153138/


¾©¹«Íø°²±¸11010802024551ºÅ