WP-DBManager 'wp-config.php' Arbitrary File Download Vulnerability
BID:47689
Info
WP-DBManager 'wp-config.php' Arbitrary File Download Vulnerability
| Bugtraq ID: | 47689 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 03 2011 12:00AM |
| Updated: | May 03 2011 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Lester Chan WP-DBManager 2.6.1 |
| Not Vulnerable: |
Lester Chan WP-DBManager 2.6.2 |
Discussion
WP-DBManager 'wp-config.php' Arbitrary File Download Vulnerability
WP-DBManager is prone to a vulnerability that lets attackers to download arbitrary files because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to download the 'wp-config.php' script. This may allow attacker to gain access to sensitive information.
WP-DBManager is prone to a vulnerability that lets attackers to download arbitrary files because the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to download the 'wp-config.php' script. This may allow attacker to gain access to sensitive information.
Exploit / POC
WP-DBManager 'wp-config.php' Arbitrary File Download Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
WP-DBManager 'wp-config.php' Arbitrary File Download Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for details.
Solution:
The vendor released an update to address this issue. Please see the references for details.
References
WP-DBManager 'wp-config.php' Arbitrary File Download Vulnerability
References:
References:
- WordPress Homepage (WordPress)
- WP-DBManager Release Notes (Lester Chan)