WordPress 的 WP BackItUp Community Edition 插件在所有版本中(包括 2.1.0 及更早版本)均存在目录遍历(Directory Traversal)漏洞,该漏洞通过 参数触发。此漏洞使得具有管理员级别或更高权限的已认证攻击者能够读取服务器上的任意文件内容,而这些文件可能包含敏感信息。处理程序中现有的 规范化操作仅在被遍历的目标路径不存在时才会执行,因此对于读取已存在的文件几乎没有防护作用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cssimmon | WP BackItUp Community Edition | 0 ~ 2.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet