1 results (0.021 seconds)

CVSS: 7.5EPSS: 10%CPEs: 1EXPL: 3

Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. Vulnerabilidad de salto de directorio en download.php en el plugin DB Backup 4.5 y anteriores para Wordpress permite a atacantes remotos leer ficheros arbitrarios a través de un .. (punto punto) en el parámetro file. • https://www.exploit-db.com/exploits/35378 http://seclists.org/oss-sec/2014/q4/1059 https://exchange.xforce.ibmcloud.com/vulnerabilities/99368 https://wpvulndb.com/vulnerabilities/7726 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •