CVE-2011-4342 – BackWPup <= 1.7.1 - Remote File Inclusion
https://notcve.org/view.php?id=CVE-2011-4342
PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpabs parameter. Vulnerabilidad de inclusión remota de archivo PHP enwp_xml_export.php en el plugin BackWPup anterior a v1.7.2 para WordPress permite a atacantes remotos ejecutar código PHP de su elección a través de la URL en el parámetro wpabs. • https://www.exploit-db.com/exploits/17056 http://packetstormsecurity.org/files/view/99799/SOS-11-003.txt http://seclists.org/fulldisclosure/2011/Mar/328 http://secunia.com/advisories/43565 http://wordpress.org/support/topic/plugin-backwpup-remote-and-local-codeexecution-vulnerability-sos-11-003 http://www.exploit-db.com/exploits/17056 http://www.openwall.com/lists/oss-security/2011/11/22/10 http://www.openwall.com/lists/oss-security/2011/11/22/7 http://www.osvdb.org/7 • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') •
CVE-2011-5208 – BackWPup – WordPress Backup Plugin < 1.4.1 - Directory Traversal
https://notcve.org/view.php?id=CVE-2011-5208
Multiple directory traversal vulnerabilities in the BackWPup plugin before 1.4.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the wpabs parameter to (1) app/options-view_log-iframe.php or (2) app/options-runnow-iframe.php. Múltiples vulnerabilidades de salto de directorio en el plugin BackWPup anterior a v1.4.1 para WordPress permite a atacantes remotos leer ficheros arbitrarios mediante un .. (punto punto) en el parámetro wpabs para (1) app/options-view_log-iframe.php o (2) app/options-runnow-iframe.php. • http://archives.neohapsis.com/archives/fulldisclosure/2011-02/0663.html http://secunia.com/advisories/43565 http://wordpress.org/extend/plugins/backwpup/changelog http://www.osvdb.org/71242 http://www.osvdb.org/71243 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •