mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 19:17:37 +02:00
892 B
892 B
CVE-2014-9119
Description
Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
POC
Reference
- http://seclists.org/oss-sec/2014/q4/1059
- http://seclists.org/oss-sec/2014/q4/1059
- https://wpvulndb.com/vulnerabilities/7726
- https://wpvulndb.com/vulnerabilities/7726