Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-24370 PoC — WordPress和Fancy Product Designer 代码问题漏洞

Source
Associated Vulnerability
Title:WordPress和Fancy Product Designer 代码问题漏洞 (CVE-2021-24370)
Description:WordPress是WordPress(Wordpress)基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 WordPress插件 Fancy Product Designer 存在代码问题漏洞,该漏洞源于“wp-admin”或“wp-content/plugins/fancy-product-designer/inc”中文件上传时对文件的验证不足。远程攻击者可利用该漏洞上传恶意文件并在服务器上执行。以下产品和版本的影响:Fancy Product D
Description
WordPress Fancy Product Designer plugin before 4.6.9 is susceptible to an arbitrary file upload. An attacker can upload malicious files and execute code on the server, modify data, and/or gain full control over a compromised system without authentication.
File Snapshot

id: CVE-2021-24370 info: name: WordPress Fancy Product Designer <4.6.9 - Arbitrary File Upload ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.