CVE-2020-24186
CVE-2020-24186
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N
Productos afectados
n/a · n/aPoCs públicas encontradas — 11
githubgithub.com/hev0x/CVE-2020-24186-wpDiscuz-7.0.4-RCE★ 19githubgithub.com/substing/CVE-2020-24186_reverse_shell_upload★ 13githubgithub.com/Sakura-501/CVE-2020-24186-exploit★ 3githubgithub.com/GazettEl/CVE-2020-24186★ 0githubgithub.com/sec-dojo-com/CVE-2020-24186★ 0githubgithub.com/meicookies/CVE-2020-24186★ 0exploitdbwww.exploit-db.com/exploits/49967no verificadocve_referencepacketstormsecurity.com/files/163012/WordPress-wpDiscuz-7.0.4-Remote-Code-Execution.htmlno verificadocve_referencepacketstormsecurity.com/files/163302/WordPress-wpDiscuz-7.0.4-Shell-Upload.htmlno verificadoexploitdbwww.exploit-db.com/exploits/49962no verificadocve_referencepacketstormsecurity.com/files/162983/WordPress-wpDiscuz-7.0.4-Shell-Upload.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://packetstormsecurity.com/files/162983/WordPress-wpDiscuz-7.0.4-Shell-Upload.htmlhttp://packetstormsecurity.com/files/163012/WordPress-wpDiscuz-7.0.4-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/163302/WordPress-wpDiscuz-7.0.4-Shell-Upload.htmlhttps://www.wordfence.com/blog/2020/07/critical-arbitrary-file-upload-vulnerability-patched-in-wpdiscuz-plugin/