{"id":5898,"date":"2017-12-24T17:15:56","date_gmt":"2017-12-24T09:15:56","guid":{"rendered":"https:\/\/aqzt.com\/5898.html"},"modified":"2020-07-11T20:14:30","modified_gmt":"2020-07-11T12:14:30","slug":"%e3%80%90%e6%bc%8f%e6%b4%9e%e5%85%ac%e5%91%8a%e3%80%91cve-2016-10033wordpress-%e6%9c%aa%e6%8e%88%e6%9d%83%e8%bf%9c%e7%a8%8b%e4%bb%a3%e7%a0%81%e6%89%a7%e8%a1%8c%e6%bc%8f%e6%b4%9e","status":"publish","type":"post","link":"https:\/\/aqzt.com\/5898.html","title":{"rendered":"\u3010\u6f0f\u6d1e\u516c\u544a\u3011CVE-2016-10033:WordPress \u672a\u6388\u6743\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c\u6f0f\u6d1e"},"content":{"rendered":"<p><span>\u5c0a\u656c\u7684\u5b89\u5168\u7528\u6237:<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span>2017\u5e745\u67083\u65e5\uff0c\u5f00\u6e90CMS\u8f6f\u4ef6<\/span><span>WordPress<\/span><span>\u88ab\u66dd\u51fa\u591a\u4e2a<\/span><span>\u6f0f\u6d1e<\/span><span>\uff0c\u5176\u4e2d\u4e00\u4e2a\u9ad8\u5371\u6f0f\u6d1e\u53ef\u4ee5\u8fdc\u7a0b\u6267\u884c\u4efb\u610f\u4ee3\u7801\uff0c\u4ece\u800c\u83b7\u53d6<\/span><span>\u670d\u52a1<\/span><span>\u6743\u9650\u3002<\/span><span>&nbsp;<\/span><br \/>\n<span><span>\u5177\u4f53\u8be6\u60c5\u5982\u4e0b\uff0c<span>\u8bf7\u60a8\u5173\u6ce8:<\/span>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;<\/span><\/span><span>&nbsp; &nbsp;<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><strong><span><span>\u6f0f\u6d1e\u7f16\u53f7:<\/span><\/span><span><span>&nbsp;<\/span><\/span><\/strong><span>&nbsp;<\/span><br \/>\n<span>CVE-2016-10033<\/span><span>&nbsp;<\/span><br \/>\n<strong><span><span>\u6f0f\u6d1e\u540d\u79f0:<\/span><\/span><span><span>&nbsp;<\/span><\/span><\/strong><span>&nbsp;<\/span><br \/>\n<span>WordPress \u672a\u6388\u6743\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c\u6f0f\u6d1e<\/span><span>&nbsp;<\/span><br \/>\n<strong>\u5b98\u65b9\u8bc4\u7ea7:<\/strong><span>&nbsp;<\/span><br \/>\n<span><span>\u9ad8\u5371<\/span><\/span><span>&nbsp;<\/span><br \/>\n<span><span><strong>\u6f0f\u6d1e\u63cf\u8ff0:<\/strong><\/span><\/span><span>&nbsp;<\/span><br \/>\n<span>\u8be5\u6f0f\u6d1e\u5b58\u5728\u4e8e\u5e7f\u6cdb\u4f7f\u7528\u7684<\/span><span>PHPMailer mail()\u51fd\u6570\u529f\u80fd\uff0c\u901a\u8fc7\u8be5\u529f\u80fd\u53ef\u4ee5\u8fd0\u884c\u6784\u9020\u7684\u6076\u610f\u4ee3\u7801\uff0c\u89e6\u53d1\u8be5\u6f0f\u6d1e\u4ece\u800c\u5bfc\u81f4\u83b7\u53d6<span>\u7cfb\u7edf<\/span>\u6743\u9650\u3002<\/span><span>&nbsp;<\/span><br \/>\n<strong><span><span>\u6f0f\u6d1e\u5229\u7528\u6761\u4ef6\u548c\u65b9\u5f0f:&nbsp;<\/span><\/span><\/strong><span>&nbsp;<\/span><br \/>\n<span><span>\u5728\u9ed8\u8ba4<span>\u914d\u7f6e<\/span>\u3001\u65e0<span>\u63d2\u4ef6<\/span>\u3001\u65e0\u8ba4\u8bc1\u7684\u6761\u4ef6\u4e0b\u76f4\u63a5\u8fdc\u7a0b\u5229\u7528<\/span><\/span><span>&nbsp;<\/span><br \/>\n<strong><span><span>\u6f0f\u6d1e\u5f71\u54cd\u8303\u56f4:&nbsp;<\/span><\/span><\/strong><span>&nbsp;<\/span><br \/>\n<span>WordPress &lt;4.7.1<\/span><span>&nbsp;<\/span><br \/>\n<strong><span><span>\u6f0f\u6d1e\u68c0\u6d4b:<\/span><\/span><span><span>&nbsp;<\/span><\/span><\/strong><span>&nbsp;<\/span><br \/>\n<span><span>\u68c0\u67e5<\/span><\/span><span><span>\u662f\u5426\u5728\u53d7\u5f71\u54cd\u7248\u672c\u5185<\/span><\/span><span>&nbsp;<\/span><br \/>\n<strong><span>\u6f0f\u6d1e\u4fee\u590d<span>\u5efa\u8bae<\/span>(\u6216\u7f13\u89e3\u63aa\u65bd):&nbsp;<\/span><\/strong><span>&nbsp;<\/span><br \/>\n<span>\u76ee\u524d\u5df2\u7ecf\u516c\u5f00\u4e86POC\uff0c<\/span><a href=\"https:\/\/wordpress.org\/news\/2017\/01\/wordpress-4-7-1-security-and-maintenance-release\/\" id=\"url_1\" target=\"_blank\" rel=\"noopener noreferrer\">\u5b98\u65b9\u516c\u544a<\/a><span>&nbsp;\u5df2\u7ecf\u5ba3\u79f0\u57284.7.1\u7248\u672c\u5df2\u7ecf\u4fee\u590d\u8be5\u6f0f\u6d1e\uff0c\u5efa\u8bae\u7528\u6237\u5c3d\u5feb<\/span><span>\u5347\u7ea7<\/span><span>\u5230\u6700\u65b0\u7248<\/span><a href=\"https:\/\/wordpress.org\/download\/release-archive\/\" id=\"url_2\" target=\"_blank\" rel=\"noopener noreferrer\">4.7.4<\/a><span>&nbsp;\uff1a<\/span><span>&nbsp;<\/span><br \/>\n<span><span><strong>\u60c5\u62a5\u6765\u6e90:&nbsp;<\/strong><\/span><\/span><span>&nbsp;<\/span><\/p>\n<ul>\n<li>https:\/\/cxsecurity.com\/issue\/WLB-2017050014<\/li>\n<li>https:\/\/wordpress.org\/news\/2017\/01\/wordpress-4-7-1-security-and-maintenance-release\/<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u5c0a\u656c\u7684\u5b89\u5168\u7528\u6237: &nbsp; 2017\u5e745\u67083\u65e5\uff0c\u5f00\u6e90CMS\u8f6f\u4ef6WordPress\u88ab\u66dd\u51fa\u591a\u4e2a\u6f0f\u6d1e\uff0c\u5176\u4e2d\u4e00\u4e2a\u9ad8\u5371\u6f0f\u6d1e\u53ef\u4ee5\u8fdc\u7a0b\u6267\u884c\u4efb\u610f\u4ee3\u7801\uff0c\u4ece\u800c\u83b7\u53d6\u670d\u52a1\u6743\u9650\u3002&nbsp; \u5177\u4f53\u8be6\u60c5\u5982\u4e0b\uff0c\u8bf7\u60a8\u5173\u6ce8:&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;&nbsp; &nbsp; &nbsp; \u6f0f\u6d1e\u7f16\u53f7:&nbsp;&nbsp; CVE-2016-10033&nbsp; \u6f0f\u6d1e\u540d\u79f0:&nbsp;&nbsp; WordPress \u672a\u6388\u6743\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c\u6f0f\u6d1e&nbsp; \u5b98\u65b9\u8bc4\u7ea7<\/p>\n","protected":false},"author":1,"featured_media":6522,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"footnotes":""},"categories":[27],"tags":[292,107,84,236,9,82,240,221,11,228,239,285,225],"collection":[276],"_links":{"self":[{"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/posts\/5898"}],"collection":[{"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/comments?post=5898"}],"version-history":[{"count":1,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/posts\/5898\/revisions"}],"predecessor-version":[{"id":6114,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/posts\/5898\/revisions\/6114"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/media\/6522"}],"wp:attachment":[{"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/media?parent=5898"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/categories?post=5898"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/tags?post=5898"},{"taxonomy":"collection","embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/collection?post=5898"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}