WordPress Backup Plugin Database Backup Information Disclosure Vulnerability
BID:54671
Info
WordPress Backup Plugin Database Backup Information Disclosure Vulnerability
| Bugtraq ID: | 54671 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2012 12:00AM |
| Updated: | Jul 25 2012 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress Backup Plugin Database Backup Information Disclosure Vulnerability
Backup Plugin for WordPress is prone to an information-disclosure vulnerability because it fails to sufficiently validate user-supplied data.
An attacker can exploit this issue to download backup files that contain sensitive information. Information harvested may aid in launching further attacks.
Versions prior to Backup 2.1 are vulnerable.
Backup Plugin for WordPress is prone to an information-disclosure vulnerability because it fails to sufficiently validate user-supplied data.
An attacker can exploit this issue to download backup files that contain sensitive information. Information harvested may aid in launching further attacks.
Versions prior to Backup 2.1 are vulnerable.
Exploit / POC
WordPress Backup Plugin Database Backup Information Disclosure Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
WordPress Backup Plugin Database Backup Information Disclosure Vulnerability
Solution:
A vendor patch is available. Please see the references for more information.
Solution:
A vendor patch is available. Please see the references for more information.
References
WordPress Backup Plugin Database Backup Information Disclosure Vulnerability
References:
References:
- WordPress Homepage (WordPress)
- Backup Plugin (WordPress)