exploit the possibilities

WordPress Ninja Forms 3.3.13 CSV Injection

WordPress Ninja Forms 3.3.13 CSV Injection
Posted Aug 19, 2018
Authored by Mostafa Gharzi

WordPress Ninja Forms plugin version 3.3.13 suffers from a CSV injection vulnerability.

tags | exploit
MD5 | 1b70cdecd08f5915b6dd099254e2f18f

WordPress Ninja Forms 3.3.13 CSV Injection

Change Mirror Download
# Exploit Title: Wordpress Plugin Ninja Forms - CSV Injection
# Exploit Author: Mostafa Gharzi
# Website: https://www.certcc.ir
# Date: 2018-08-19
# Google Dork: N/A
# Vendor: The WP Ninjas
# Software Link: https://wordpress.org/plugins/ninja-forms/
# Affected Version: 3.3.13 and before
# Active installations: 1+ million
# Patched Version: unpatched
# Category: Web Application
# Platform: PHP
# Tested on: Win10x64 & Kali Linux

# 1. Plugin Description:
# Ninja Forms is the ultimate FREE form creation tool for WordPress. Build
forms within minutes using
# a simple yet powerful drag-and-drop form creator. For beginners, quickly
and easily design complex forms
# with absolutely no code. For developers, utilize built-in hooks, filters,
and even custom field templates
# to do whatever you need at any step in the form building or submission
using Ninja Forms as a framework.
# Input information to the form is stored and exported in a csv file.

# 2. Technical Description:
# WordPress Ninja Forms plugin version 3.3.13 and before are affected by
Remote Code Execution
# through the CSV injection vulnerability. This allows an application user
to inject commands as part
# of the fields of forms and these commands are executed when a user with
greater privilege exports
# the data in CSV and opens that file on his machine.

# 3. Proof Of Concept (PoC):
# Enter the payload =SUM(1+1)*cmd|' /C calc'!A0 in any field of the form,
for example, in name field.
# When the user with high privileges logs in to the application, export
data in CSV and opens the
# generated file, the command is executed and the calculator will run open
on the machine.

# 4. Payloads:
=SUM(1+1)*cmd|' /C calc'!A0
+SUM(1+1)*cmd|' /C calc'!A0
-SUM(1+1)*cmd|' /C calc'!A0
@SUM(1+1)*cmd|' /C calc'!A0

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

December 2019

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    1 Files
  • 2
    Dec 2nd
    16 Files
  • 3
    Dec 3rd
    17 Files
  • 4
    Dec 4th
    23 Files
  • 5
    Dec 5th
    11 Files
  • 6
    Dec 6th
    10 Files
  • 7
    Dec 7th
    1 Files
  • 8
    Dec 8th
    1 Files
  • 9
    Dec 9th
    15 Files
  • 10
    Dec 10th
    30 Files
  • 11
    Dec 11th
    8 Files
  • 12
    Dec 12th
    20 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2019 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close