
CVE-2021-24155 – Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload
https://notcve.org/view.php?id=CVE-2021-24155
18 Feb 2021 — The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE. El plugin WordPress Backup and Migrate - Backup Guard WordPress antes de la versión 1.6.0 no garantizaba que los archivos importados tuvieran el formato y la extensión SGBP, lo que permitía a los usuarios con altos privilegios (admin+) subir archiv... • https://packetstorm.news/files/id/163382 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2013-1425
https://notcve.org/view.php?id=CVE-2013-1425
07 Nov 2019 — ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions. ldap-git-backup versiones anteriores a 1.0.4, expone hashes de contraseña debido a permisos de directorio incorrectos. • https://github.com/elmar/ldap-git-backup/commit/a90f3217fce87962db82d212f73af70693087124 • CWE-276: Incorrect Default Permissions •

CVE-2014-4993
https://notcve.org/view.php?id=CVE-2014-4993
10 Jan 2018 — (1) lib/backup/cli/utility.rb in the backup-agoddard gem 3.0.28 and (2) lib/backup/cli/utility.rb in the backup_checksum gem 3.0.23 for Ruby place credentials on the openssl command line, which allows local users to obtain sensitive information by listing the process. (1) lib/backup/cli/utility.rb en la gema backup-agoddard 3.0.28 y (2) lib/backup/cli/utility.rb en la gema backup_checksum 3.0.23 para Ruby colocan credenciales en la línea de comandos de openssl. Esto permite que usuarios locales obtengan inf... • http://www.openwall.com/lists/oss-security/2014/07/07/11 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-10837 – BackupGuard <= 1.1.46 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2017-10837
24 Aug 2017 — Cross-site scripting vulnerability in BackupGuard prior to version 1.1.47 allows an attacker to inject arbitrary web script or HTML via unspecified vectors. Una vulnerabilidad de tipo Cross-Site Scripting (XSS) en BackupGuard en versiones anteriores a la 1.1.47 permite a atacantes remotos inyectar scripts web o HTML arbitrarios utilizando vectores no especificados. • https://jvn.jp/en/jp/JVN58559719/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-18488 – Backup Guard <= 1.1.46 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2017-18488
11 Aug 2017 — The Backup Guard plugin before 1.1.47 for WordPress has multiple XSS issues. El complemento Backup Guard versión anterior a 1.1.47 para WordPress tiene múltiples problemas XSS. • https://wordpress.org/plugins/backup/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-1002016 – flickr-picture-backup <= 0.7 - Arbitrary file upload
https://notcve.org/view.php?id=CVE-2017-1002016
26 Apr 2017 — Vulnerability in wordpress plugin flickr-picture-backup v0.7, The code in flickr-picture-download.php doesn't check to see if the user is authenticated or that they have permission to upload files. Existe una vulnerabilidad en el plugin flickr-picture-backup v0.7 de WordPress. El código en flickr-picture-download.php no verifica si el usuario está autenticado o tiene permisos para subir archivos. • http://www.vapidlabs.com/advisory.php?v=190 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2014-9310 – WordPress Backup to Dropbox < 4.1 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2014-9310
22 Dec 2014 — Cross-site scripting (XSS) vulnerability in the WordPress Backup to Dropbox plugin before 4.1 for WordPress. Vulnerabilidad de tipo Cross-site scripting (XSS) en el plugin WordPress Backup to Dropbox, en versiones anteriores a la 4.1. • http://www.securityfocus.com/bid/75082 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-9119 – DB Backup < 5.0 - Directory Traversal
https://notcve.org/view.php?id=CVE-2014-9119
16 Dec 2014 — Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. Vulnerabilidad de salto de directorio en download.php en el plugin DB Backup 4.5 y anteriores para Wordpress permite a atacantes remotos leer ficheros arbitrarios a través de un .. (punto punto) en el parámetro file. • https://www.exploit-db.com/exploits/35378 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2014-10076 – Database Backup for WordPress <= 2.2.4 - Missing Authorization
https://notcve.org/view.php?id=CVE-2014-10076
02 Nov 2014 — The wp-db-backup plugin 2.2.4 for WordPress relies on a five-character string for access control, which makes it easier for remote attackers to read backup archives via a brute-force attack. El plugin wp-db-backup 2.2.4 para WordPress se basa en una cadena de cinco caracteres para el control de acceso, lo que facilita a los atacantes remotos la lectura de archivos de copia de seguridad mediante un ataque por fuerza bruta. The wp-db-backup plugin up to 2.2.4 for WordPress relies on a five-character string fo... • http://www.vapidlabs.com/advisory.php?v=81 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-862: Missing Authorization •

CVE-2014-3114 – EZPZ One Click Backup <= 12.03.10 - Unauthenticated Command Injection
https://notcve.org/view.php?id=CVE-2014-3114
01 Aug 2014 — The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to execute arbitrary commands via the cmd parameter to functions/ezpz-archive-cmd.php. El plugin EZPZ One Click Backup (ezpz-one-click-backup), en versiones 12.03.10 y anteriores para WordPress, permite que atacantes remotos ejecuten comandos arbitrarios mediante el parámetro cmd en functions/ezpz-archive-cmd.php. • http://www.openwall.com/lists/oss-security/2014/05/01/11 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •