importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, which allows remote attackers to obtain sensitive information, or overwrite or delete files, via vectors involving a (1) direct request, (2) step=1 request, (3) step=2 or step=3 request, or (4) step=7 request.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/fulldisclosure/2013-03/0205.html | Exploit |
http://packetstormsecurity.com/files/120923 | Exploit |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2013-04-02 05:09
Updated : 2013-04-02 05:09
NVD link : CVE-2013-2741
Mitre link : CVE-2013-2741
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
ithemes
- backupbuddy
wordpress
- wordpress