vendor:
Wordpress Plugin BackWPup
by:
Phil Taylor - Sense of Security Labs.
7.5
CVSS
HIGH
Wordpress Plugin BackWPup
Not available
CWE
Product Name: Wordpress Plugin BackWPup
Affected Version From: 1.6.2001
Affected Version To: 1.6.2001
Patch Exists: YES
Related CWE: Not yet assigned
CPE: Not available
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Independent
2011
Sense of Security – Security Advisory – SOS-11-003
A vulnerability has been discovered in the Wordpress plugin BackWPup 1.6.1 which can be exploited to execute local or remote code on the web server. The Input passed to the component 'wp_xml_export.php' via the 'wpabs' variable allows the inclusion and execution of local or remote PHP files as long as a '_nonce' value is known. The '_nonce' value relies on a static constant which is not defined in the script meaning that it defaults to the value '822728c8d9'.
Mitigation:
Upgrade to version 1.7.1