漏洞信息详情
WP-DB Backup WordPress ‘wp-db-backup.php’目录遍历漏洞
- CNNVD编号:CNNVD-200608-295
- 危害等级: 中危
- CVE编号:
CVE-2006-4208
- 漏洞类型:
路径遍历
- 发布时间:
2006-08-17
- 威胁类型:
远程
- 更新时间:
2006-08-24
- 厂 商:
skippy.net - 漏洞来源:
marc & shb from ss… -
漏洞简介
WordPress 1.7及早期版本的Skippy WP-DB-Backup插件中的wp-db-backup.php脚本存在目录遍历漏洞,有管理员特权的远程认证用户可借助edit.php脚本的backup参数中(该参数中包含..)读取任意文件。
漏洞公告
WordPress WordPress 2.0
WordPress WordPress Latest Release Download
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.0.1
WordPress WordPress Latest Release Download
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.0.2
WordPress WordPress Latest Release Download
http://wordpress.org/latest.tar.gz
参考网址
来源: XF
名称: wpdbbackup-edit-directory-traversal(28375)
链接:http://xforce.iss.net/xforce/xfdb/28375
来源: www.skippy.net
链接:http://www.skippy.net/blog/category/wordpress/plugins/wp-db-backup/
来源: BID
名称: 19504
链接:http://www.securityfocus.com/bid/19504
来源: BUGTRAQ
名称: 20060814 WordPress WP-DB Backup Plugin Directory Traversal Vulnerability
链接:http://www.securityfocus.com/archive/1/archive/1/443181/100/0/threaded
来源: VUPEN
名称: ADV-2006-3280
链接:http://www.frsirt.com/english/advisories/2006/3280
来源: trac.wordpress.org
链接:http://trac.wordpress.org/changeset/4095
来源: SECUNIA
名称: 21486
链接:http://secunia.com/advisories/21486
来源: SREASON
名称: 1401