关联漏洞
描述
Automatic Plugin for WordPress < 3.92.1 Multiples Vulnerabilities
介绍
# ⚠️ CVE-2024-27954
💀 **Automatic Remote code Execution Exploit Tools | By GhostSec** 💀
---
## 📝 Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue affects Automatic: from n/a through 3.92.0.
### ⌛ Queries
- FOFA = `body="wp-content/plugins/wp-automatic" && header="HTTP/1.1 200 OK"`
- ZoomEye = `title:"wp-automatic" response.status_code:200`
- Shodan = `http.title:"wp-automatic" http.status:200`
- Publicwww = `"/wp-content/plugins/wp-automatic"`
## ⌛ Installation
1. **Clone the repository:**
```bash
git clone https://github.com/fa-rrel/CVE-2024-27954.git
cd CVE-2024-27954
```
2. **Install the required packages:**
```bash
pip install -r requirements.txt
```
---
## 🚀 Usage
- RCE Usage
```bash
python RCE_Exploit.py -u <target_url> or <File.txt>
```
- Nuclei usage
```bash
nuclei -t POC.yaml --target http://testphp.vulnweb.com/ or -l WPUrls.txt
```
## ☕ Support
If you find this tool useful and want to support the development, consider buying me a coffee:
<a href="https://buymeacoffee.com/ghost_sec" target="_blank"><img src="https://cdn.buymeacoffee.com/buttons/v2/arial-white.png" alt="Buy Me a Coffee" width="90"></a>
---
## ⚠️ Disclaimer
This tool is intended for authorized security testing and educational purposes only. Unauthorized use against systems is strictly prohibited.
## 📄 License
This is tools licensed under the MIT License.
文件快照
[4.0K] /data/pocs/a7386c63ae5cc9e9749b1239955b42c5ed73387f
├── [ 661] POC.yaml
├── [4.1K] RCE_Exploit.py
├── [1.5K] README.md
└── [ 26] requirements.txt
0 directories, 4 files
备注
1. 建议优先通过来源进行访问。
2. 如果因为来源失效或无法访问,请发送邮箱到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
3. 神龙已为您对POC代码进行快照,为了长期维护,请考虑为本地POC付费,感谢您的支持。