关联漏洞
            
        
            描述
            Automatic Plugin for WordPress < 3.92.1 Multiples Vulnerabilities
        
        
            介绍
            
# ⚠️ CVE-2024-27954
💀 **Automatic Remote code Execution Exploit Tools | By GhostSec** 💀
---
## 📝 Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue affects Automatic: from n/a through 3.92.0.
### ⌛ Queries
- FOFA = `body="wp-content/plugins/wp-automatic" && header="HTTP/1.1 200 OK"`
- ZoomEye = `title:"wp-automatic" response.status_code:200`
- Shodan = `http.title:"wp-automatic" http.status:200`
- Publicwww = `"/wp-content/plugins/wp-automatic"`
## ⌛ Installation
1. **Clone the repository:**
   ```bash
   git clone https://github.com/fa-rrel/CVE-2024-27954.git
   cd CVE-2024-27954
   ```
2. **Install the required packages:**
   ```bash
   pip install -r requirements.txt
   ```
---
## 🚀 Usage
- RCE Usage
```bash
python RCE_Exploit.py -u <target_url> or <File.txt>
```
- Nuclei usage
```bash
nuclei -t POC.yaml --target http://testphp.vulnweb.com/ or -l WPUrls.txt
```
## ☕ Support
If you find this tool useful and want to support the development, consider buying me a coffee:
<a href="https://buymeacoffee.com/ghost_sec" target="_blank"><img src="https://cdn.buymeacoffee.com/buttons/v2/arial-white.png" alt="Buy Me a Coffee" width="90"></a>
---
## ⚠️ Disclaimer
This tool is intended for authorized security testing and educational purposes only. Unauthorized use against systems is strictly prohibited.
## 📄 License
This is tools licensed under the MIT License.
        
        文件快照
        
            
                
 [4.0K]  /data/pocs/6077969b83913072b492c98910205c840ebb5748
├── [ 661]  POC.yaml
├── [4.1K]  RCE_Exploit.py
├── [1.5K]  README.md
└── [  26]  requirements.txt
0 directories, 4 files
                
             
         
        备注
        
            
                1. 建议优先通过来源进行访问。
                2. 如果因为来源失效或无法访问,请发送邮箱到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
                3. 神龙已为您对POC代码进行快照,为了长期维护,请考虑为本地POC付费,感谢您的支持。