Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-17574 PoC — WordPress Popup Maker插件安全漏洞

Source
Associated Vulnerability
Title:WordPress Popup Maker插件安全漏洞 (CVE-2019-17574)
Description:WordPress是WordPress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。Popup Maker是使用在其中的一个弹出窗口插件。 WordPress Popup Maker插件1.8.13之前版本中存在安全漏洞。攻击者可利用该漏洞检索有关WordPress插件、Webserver配置、PHP配置等信息。
Description
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the "support debug text file").
File Snapshot

id: CVE-2019-17574 info: name: Popup-Maker < 1.8.12 - Broken Authentication author: DhiyaneshDK ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.