WordPress 的 All-in-One WP Migration and Backup 插件在 7.109 及更早版本中,其归档恢复功能存在 SQL 注入漏洞。该漏洞是由于对用户提供的参数缺乏足够的转义处理,且在构建 SQL 查询时未使用充分的预处理机制所致。这使得未经身份验证的攻击者能够将额外的 SQL 查询附加到现有查询中,从而从数据库中提取敏感信息。 一旦网站管理员执行归档恢复操作,攻击者可利用此漏洞获取 值;进而通过利用该密钥,最终实现远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| servmask | All-in-One WP Migration and Backup | ≤ 7.109 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| servmask | All-in-One WP Migration and Backup | 0 ~ 7.109 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet