Back to search
CVE-2006-5705
Published: Nov 4, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in WordPress before 2.0.5 allow remote authenticated users to read or overwrite arbitrary files via directory traversal sequences in the (1) backup and (2) fragment parameters in a GET request.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://markjaquith.wordpress.com/2006/10/17/changes-in-wordpress-205/
x_refsource_CONFIRM
http://wordpress.org/development/2006/10/205-ronan/
x_refsource_CONFIRM
GLSA-200611-10
vendor-advisory
x_refsource_GENTOO
OpenPKG-SA-2006.027
vendor-advisory
x_refsource_OPENPKG
22942
third-party-advisory
x_refsource_SECUNIA
20869
vdb-entry
x_refsource_BID
22683
third-party-advisory
x_refsource_SECUNIA
http://trac.wordpress.org/changeset/4226
x_refsource_CONFIRM
http://bugs.gentoo.org/show_bug.cgi?id=153303
x_refsource_CONFIRM
ADV-2006-4307
vdb-entry
x_refsource_VUPEN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now