Vulnerabilities > CVE-2006-4208 - Directory Traversal vulnerability in Skippy.Net Wp-Db Backup Plugin for Wordpress 1.6/1.7

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
skippy-net
exploit available

Summary

Directory traversal vulnerability in wp-db-backup.php in Skippy WP-DB-Backup plugin for WordPress 1.7 and earlier allows remote authenticated users with administrative privileges to read arbitrary files via a .. (dot dot) in the backup parameter to edit.php. Apply patch

Exploit-Db

descriptionWP-DB Backup For Wordpress 1.6/1.7 Edit.PHP Directory Traversal Vulnerability. CVE-2006-4208. Webapps exploit for php platform
idEDB-ID:28382
last seen2016-02-03
modified2006-08-14
published2006-08-14
reportermarc & shb
sourcehttps://www.exploit-db.com/download/28382/
titleWP-DB Backup For WordPress 1.6/1.7 Edit.PHP - Directory Traversal Vulnerability