RSS   Podatności dla 'Backupbuddy'   RSS

2013-04-02
 
CVE-2013-2744

CWE-200
 

 
importbuddy.php in the BackupBuddy plugin 2.2.25 for WordPress allows remote attackers to obtain configuration information via a step 0 phpinfo action, which calls the phpinfo function.

 
 
CVE-2013-2743

CWE-287
 

 
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentication via a crafted integer in the step parameter.

 
 
CVE-2013-2742

CWE-DesignError
 

 
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not reliably delete itself after completing a restore operation, which makes it easier for remote attackers to obtain access via subsequent requests to this script.

 
 
CVE-2013-2741

CWE-287
 

 
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, which allows remote attackers to obtain sensitive information, or overwrite or delete files, via vectors involving a (1) direct request, (2) step=1 request, (3) step=2 or step=3 request, or (4) step=7 request.

 

 >>> Vendor: Ithemes 15 Produkty
Backupbuddy
Security
Mobile
Authorize.net
Exchange
Builder theme depot
Builder theme market
Builder style manager
Easy canadian sales taxes
Stripe
Invoices
Manual purchases
Membership
Paypal pro
Ithemes security


Copyright 2024, cxsecurity.com

 

Back to Top