WP-DB Backup WordPress ‘wp-db-backup.php’目录遍历漏洞

漏洞信息详情

WP-DB Backup WordPress ‘wp-db-backup.php’目录遍历漏洞

漏洞简介

WordPress 1.7及早期版本的Skippy WP-DB-Backup插件中的wp-db-backup.php脚本存在目录遍历漏洞,有管理员特权的远程认证用户可借助edit.php脚本的backup参数中(该参数中包含..)读取任意文件。

漏洞公告

WordPress WordPress 2.0

WordPress WordPress Latest Release Download

http://wordpress.org/latest.tar.gz

WordPress WordPress 2.0.1

WordPress WordPress Latest Release Download

http://wordpress.org/latest.tar.gz

WordPress WordPress 2.0.2

WordPress WordPress Latest Release Download

http://wordpress.org/latest.tar.gz

参考网址

来源: XF

名称: wpdbbackup-edit-directory-traversal(28375)

链接:http://xforce.iss.net/xforce/xfdb/28375

来源: www.skippy.net

链接:http://www.skippy.net/blog/category/wordpress/plugins/wp-db-backup/

来源: BID

名称: 19504

链接:http://www.securityfocus.com/bid/19504

来源: BUGTRAQ

名称: 20060814 WordPress WP-DB Backup Plugin Directory Traversal Vulnerability

链接:http://www.securityfocus.com/archive/1/archive/1/443181/100/0/threaded

来源: VUPEN

名称: ADV-2006-3280

链接:http://www.frsirt.com/english/advisories/2006/3280

来源: trac.wordpress.org

链接:http://trac.wordpress.org/changeset/4095

来源: SECUNIA

名称: 21486

链接:http://secunia.com/advisories/21486

来源: SREASON

名称: 1401

链接:http://securityreason.com/securityalert/1401

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享