WordPress Ad Inserter²å¼þÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-07-17Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.9£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ÊÊÓÃÓÚWordPress Ad Inserter²å¼þ<= 2.4.21¡£¡£¡£¡£¡£
Îó²î¸ÅÊö
WordPressÊÇWordPress»ù½ð»áµÄÒ»Ì×ʹÓÃPHPÓïÑÔ¿ª·¢µÄ²©¿Íƽ̨¡£¡£¡£¡£¡£¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄЧÀÍÆ÷ÉϼÜÉèСÎÒ˽¼Ò²©¿ÍÍøÕ¾¡£¡£¡£¡£¡£Ad InserterÊÇÒ»¿îÕë¶ÔWordpressµÄ¹ã¸æ²å¼þ£¬£¬£¬£¬£¬£¬¾ß±¸Ðí¶à¸ß¼¶µÄ¹ã¸æÖÎÀí¹¦Ð§£¬£¬£¬£¬£¬£¬×ÊÖúÎÒÃÇÔÚWordpressÍøÕ¾í§ÒâλÖòåÈëͶ·Å¹ã¸æ´úÂëºÍͶ·ÅÏÔʾ¹ã¸æ¡£¡£¡£¡£¡£²¢ÇÒ¿ÉÒÔÖ§³ÖÖÖÖÖ¹ã¸æ£¬£¬£¬£¬£¬£¬°üÀ¨Google AdSense¹ã¸æ£¬£¬£¬£¬£¬£¬ÄÚÈÝÏà¹ØµÄÑÇÂíÑ·ÔÉú¹ºÎï¹ã¸æ£¬£¬£¬£¬£¬£¬Media.net¹ã¸æºÍÂÖ²¥ºá·ù¹ã¸æµÈ¡£¡£¡£¡£¡£
¸ÃÎó²îÔ´ÓÚʹÓÃcheck_admin_referer£¨£©¾ÙÐÐÊÚȨ£¬£¬£¬£¬£¬£¬ËüÊÇרÃÅÓÃÓÚ±£»£»£»¤WordPressÕ¾µãÃâÊÜʹÓÃnonceµÄ¿çÕ¾µãÇëÇóαÔ죨CSRF£©¹¥»÷¡£¡£¡£¡£¡£Ò»µ©¹¥»÷ÕßÓµÓÐÒ»¸önonce¿É¹©ËûʹÓ㬣¬£¬£¬£¬£¬Ëû¾Í¿ÉÒÔÁ¬Ã¦´¥·¢µ÷ÊÔ¹¦Ð§£¬£¬£¬£¬£¬£¬ÉõÖÁͨ¹ý·¢ËͰüÀ¨í§ÒâPHP´úÂëµÄ¶ñÒâ¸ºÔØÀ´Ê¹ÓÃ¹ã¸æÔ¤ÀÀ¹¦Ð§¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
https://wordpress.org/plugins/ad-inserter/#developers¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ