Extension WordPress
Vulnérabilités BackupBuddy
Cette page rassemble les failles publiées pour BackupBuddy, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de BackupBuddy
6 fiches
BackupBuddy <= 8.8.2 – Reflected Cross-Site Scripting
The BackupBuddy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting several parameters in versions up to, and including, 8.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-8.8.2
8.8.3
30/01/2023
BackupBuddy 8.5.8.0 – 8.7.4.1 – Arbitrary File Download
The BackupBuddy plugin for WordPress is vulnerable to unauthenticated arbitrary file downloads via the 'local-download' found in the backupbuddy_local_download() function in versions 8.5.8.0 to 8.7.4.1. This is due to a missing capability check and nonce check on the…
8.5.8.0-8.7.4.1
8.7.5
06/09/2022
BackupBuddy < 3.0 – Authentication Bypass
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentication via a crafted integer in the step parameter.
[*, 3.0)
3.0
24/03/2013
BackupBuddy < 3.0 – Authentication Bypass
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not reliably delete itself after completing a restore operation, which makes it easier for remote attackers to obtain access via subsequent requests to this…
[*, 3.0)
3.0
24/03/2013
BackupBuddy < 3.0 – Authentication Bypass
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, which allows remote attackers to obtain sensitive information, or overwrite or delete files, via vectors involving a (1)…
[*, 3.0)
3.0
24/03/2013
BackupBuddy <= 2.2.28 – Sensitive Information Disclosure
The BackupBuddy plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.2.28 via a step 0 phpinfo action, which calls the phpinfo function. This can allow remote attackers to extract configuration information.
[*, 3.0)
3.0
24/03/2013
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.