========================================================== Wordpress plugin LayerSlider WP Version 4.6.1 (Possible all versions) suffers from CSRF And from Directory Traversal Vulnerabilities. AFAIK multiple wordpress themes uses this plugin. And one of them is satellite - v1.0.2 wordpress theme. ========================================================== Tested on: Server version: Apache/2.4.7 (Fedora) Server built: Mar 3 2014 12:12:09 $ php -v PHP 5.5.10 (cli) (built: Mar 5 2014 17:13:58) Copyright (c) 1997-2014 The PHP Group Zend Engine v2.5.0, Copyright (c) 1998-2014 Zend Technologies Wordpress 3.8.1 (Fresh install) Theme Default package: satellite - v1.0.2 + LayerSlider WP Version 4.6.1 (plugin) Note 1: (That vulnerable plugin LayerSlider WP Version 4.6.1 default comes with satellite - v1.0.2 WP theme). find `pwd`/ -name '*.zip' /var/www/hacker1.own/wp-content/themes/satellite/plugins/layersliderwp-4.6.1.installable.zip CSRF Defaced url can be found here: http://owned.tld/wp-content/uploads/layerslider.custom.css ============CSRF 1======================================================
=========== CSRF 2===================================================== Defaced URL can be found here: http://owned.tld/wp-content/plugins/LayerSlider/skins/noskin/skin.css ========================================================================
========================================================================= Directory Traversal/This may lead also to Arbitrary code execution/Arbitrary File read (This can be combined with CSRF onfly and may cause successfull Happy Travel on server.) [blackhat@localhost] LayerSlider]# pwd && cat -b editor.php /var/www/hacker1.own/wp-content/plugins/LayerSlider 1 21
22 23
24

25 26 27

28 29
30 31 32
33

34 35

36 37 49

50

51
52 53 54

55 56 Codex for more information.', 'LayerSlider') ?> 57 58 59 60 61

62
63
64
[blackhat@localhost LayerSlider]# ===================== WITH LOVE FROM AZERBAIJAN ======================== packetstormsecurity.org packetstormsecurity.com packetstormsecurity.net securityfocus.com cxsecurity.com security.nnov.ru securtiyvulns.com securitylab.ru secunia.com securityhome.eu exploitsdownload.com osvdb.com websecurity.com.ua 1337day.com itsecuritysolutions.org waraxe.us exploit-db.com insecurety.net millikuvvetler.net b3yaz.org Special respect's to CAMOUFL4G3 && ottoman38 and to all Azerbaijan Black hatz,Aa team && to All Turkish hackers. /AkaStep