WordPress Bliss Gallery插件 任意文件上传漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 0x00 概述 插件版本`version 2.3`,PoC附插件网盘下载地址 ### 0x01 漏洞分析 漏洞出现在`wp-content\plugins\wp-bliss-gallery\html\manage.php`, ``` <?php ... $cpage = 'admin.php?page='.$_REQUEST['page']; ?> <div class="wrap"> <h2><?php _e('Category Management'); ?><a href="javascript:;" id="add_new_album" class="add-new-h2"><?php _e('Add New'); ?></a></h2> <form id="add_new_album_form" action="" method="post" enctype="multipart/form-data"> <input type="hidden" name="task" value="uni_add_new_album" /> <table> <tr> <td><label><?php _e('Category Name'); ?></label></td> <td><input type="text" id="album_name" name="album_name" value="" /></td> </tr> <tr> <td><label><?php _e('Category Description'); ?></label></td> <td><textarea id="album_desc" name="album_desc"></textarea></td> </tr> <tr> <td><label><?php _e('Category Image'); ?></label></td> <td><input type="file" name="album_img" value="" /></td> </tr> </table> <p> <button type="submit" class="button-primary"><?php _e('Save'); ?></button> </p> </form> ```...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息