WordPress DB Backup Plugin 'download.php' Directory Traversal Vulnerability
BID:71702
Info
WordPress DB Backup Plugin 'download.php' Directory Traversal Vulnerability
| Bugtraq ID: | 71702 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-9119 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2014 12:00AM |
| Updated: | Dec 16 2014 12:00AM |
| Credit: | Henri Salo |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress DB Backup Plugin 'download.php' Directory Traversal Vulnerability
DB Backup plugin for WordPress is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks.
DB Backup 4.5 and prior versions are vulnerable.
DB Backup plugin for WordPress is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks.
DB Backup 4.5 and prior versions are vulnerable.
Exploit / POC
WordPress DB Backup Plugin 'download.php' Directory Traversal Vulnerability
Attackers can exploit this issue using browser.
The following example URI is available:
www.example.com/wp-content/plugins/db-backup/download.php?file=../../../wp-config.php
Attackers can exploit this issue using browser.
The following example URI is available:
www.example.com/wp-content/plugins/db-backup/download.php?file=../../../wp-config.php
Solution / Fix
WordPress DB Backup Plugin 'download.php' Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].