WordPress Core <= 2.0.3 - Denial of Service

2006-07-29 00:00
Anonymous

Strategic Overview

Status
Patched in 2.0.4
Affected CoreWordPress 2.0
Affected Version<= 2.0.3
CVSS6.5Medium
CVECVE-2008-0194
View all WordPress 2.0 vulnerabilities

Vulnerability Overview

Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrary files, and cause a denial of service via a .. (dot dot) in the backup parameter in a wp-db-backup.php action to wp-admin/edit.php. NOTE: this might be the same as CVE-2006-5705.1.

Technical Analysis

REMEDIATION: Update to version 2.0.4, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C