WP-DB Backup 1.7 directory traversal exploit
Posted By Raymond In Category: Computer
29
2006
The famous WP-DB Backup plugin for WordPress is vulnerable to directory traversal attack. marc & shb from ssteam discovered this vulnerability about a week ago and the author of WP-DB Backup was not informed about it.
Proof of Concept:
You must have administrator rights in the wordpress blog to exploit this vulnerability.
http://path-to-wordpress/wp-admin/edit.php?page=wp-db-backup.php&backup=
../../../../../etc/passwd
The author of WP-DB Backup currently doesn’t have a fix for this exploit. Disabling the plugin will not fix the problem. You can either rename or delete the plugin for temporary fix. If your wordpress blog site has a few admins, then you definately need to fix this problem.
Good news is, Ryan Boren has a fix for the directory traversal vulnerability.
Related posts:
Recent Posts
- Enable Cancel Sent Email Feature in Gmail
- How to Shut Down in Windows 8
- FTP Droplet Allows Uploading Files Without Knowing FTP Login Details
- Disable UAC for Specific Software in Windows 7 with UAC Trust Shortcut
- A Sad Day…
- Google Books Downloader Saves eBooks in PDF or Images
- IntelliAdmin USB History Viewer
Pingback: Topic Celtic gold rings - Public Forum