漏洞概述 漏洞名称: Buddypress Xprofile Custom Fields Type 2.6.3 - Remote Code Execution EDB-ID: 44432 作者: LENON LEITE 类型: WEBAPPS 平台: PHP 日期: 2018-04-09 版本: 2.6.3 测试环境: Ubuntu 10.1 影响范围 受影响应用: Buddypress Xprofile Custom Fields Type 2.6.3 漏洞类型: 远程代码执行 (RCE) 修复方案 建议: 更新到最新版本或应用官方提供的补丁。 POC代码 ```bash Exploit Title: Plugin Buddypress Xprofile Custom Fields Type 2.6.3 RCE - Unlink Date: 08/04/2018 Exploit Author: Lenon Leite Vendor Homepage: https://wordpress.org/plugins/buddypress-xprofile-custom-fields-type/ Software Link: https://wordpress.org/plugins/buddypress-xprofile-custom-fields-type/ Contact: http://twitter.com/lenonleite Website: http://lenonleite.com.br/ Category: webapps Version: 2.6.3 Tested on: Ubuntu 10.1 Article: http://lenonleite.com.br/publish-exploits/plugin-buddypress-xprofile-custom-fields-type-2-6-3-rce-unlink/ Login as regular user. 1 - Log in with Buddypress User 2 - Access Edit Profile: http://target/members/admin/profile/edit/ 3 - Register data with Unage: 4 Change parameter to delete Unage in html and save profile; #-- #Atenciosamente #Lenon Leite