Twenty Year Anniversary

WordPress Google Analyticator 6.4.9.3 CSRF

WordPress Google Analyticator 6.4.9.3 CSRF
Posted Jun 20, 2015
Authored by Nitin Venkatesh

WordPress Google Analyticator plugin version 6.4.9.3 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
MD5 | baa9761e9f622915ccdcf67a11c1eedf

WordPress Google Analyticator 6.4.9.3 CSRF

Change Mirror Download
# Title: Cross-Site Request Forgery in Google Analyticator Wordpress Plugin
v6.4.9.3 before rev @1183563
# Submitter: Nitin Venkatesh
# Product: Google Analyticator Wordpress Plugin
# Product URL: https://wordpress.org/plugins/google-analyticator/
# Vulnerability Type: Cross-Site Request Forgery [CWE-352]
# Affected Versions: v6.4.9.3 before rev @1183563 and possibly earlier
# Tested versions: v6.4.9.3 rev @1168849
# Fixed Version: v6.4.9.3 rev @1183563
# Link to code diff: https://plugins.trac.wordpress.org/changeset/1183563/
# CVE Status: None/Unassigned/Fresh

## Product Information:

Google Analyticator makes it super easy to view Google Analytics within
your WordPress dashboard. This eliminates the need to edit your template
code to begin logging. Google Analyticator also includes several widgets
for displaying Analytics data in the admin and on your blog.

One of the most popular WordPress plugins for Google Analytics! Over 3.5+
million downloads.

## Vulnerability Description:

The administrative actions allowed by the plugin can be exploited using
CSRF which could be used to disrupt the functionality provided by the
plugin.

## Proof-of-Concept:

http://localhost/wp-admin/options-general.php?page=google-analyticator.php&pageaction=ga_clear_cache

http://localhost/wp-admin/options-general.php?page=ga_reset

## Solution:

Upgrade to v6.4.9.3 rev @1183563

## Disclosure Timeline:

2015-05-30 - Contacted developer via forums.
2015-06-02 - Vulnerability details submitted on the forums on developer's
request -
https://wordpress.org/support/topic/discovered-security-vulnerabilities-1
2015-06-13 - Re-contacted developer on the forums.
2015-06-18 - Update released.
2015-06-19 - Publishing to Full Disclosure mailing list

## Disclaimer:

This disclosure is purely meant for educational purposes. I will in no way
be responsible as to how the information in this disclosure is used.


Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

Want To Donate?


Bitcoin: 18PFeCVLwpmaBuQqd5xAYZ8bZdvbyEWMmU

File Archive:

July 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    1 Files
  • 2
    Jul 2nd
    26 Files
  • 3
    Jul 3rd
    15 Files
  • 4
    Jul 4th
    11 Files
  • 5
    Jul 5th
    13 Files
  • 6
    Jul 6th
    4 Files
  • 7
    Jul 7th
    4 Files
  • 8
    Jul 8th
    1 Files
  • 9
    Jul 9th
    16 Files
  • 10
    Jul 10th
    15 Files
  • 11
    Jul 11th
    32 Files
  • 12
    Jul 12th
    22 Files
  • 13
    Jul 13th
    15 Files
  • 14
    Jul 14th
    1 Files
  • 15
    Jul 15th
    1 Files
  • 16
    Jul 16th
    3 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close