Extension WordPress
Vulnérabilités WP-DBManager
Cette page rassemble les failles publiées pour WP-DBManager, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP-DBManager
5 fiches
WP-DBManager <= 2.80.7 – Authenticated (Admin+) Remote Code Execution on Multi-Site
The WP-DBManager plugin for WordPress is vulnerable to remote code execution due to an incorrect capability check in the ~/database-backup.php file in versions up to, and including, 2.80.7. This makes it possible for high level authenticated users, such…
*-2.80.7
2.80.8
25/07/2022
WP-DBManager <= 2.79.1 – Directory Traversal Allowing Arbitrary File Deletion
The WP-DBManager plugin for WordPress is vulnerable to Directory Traversal allowing arbitrary file deletion in versions up to, and including, 2.79.1. This allows authenticated high-privilege attackers to delete arbitrary files, which can be used to reset a site…
[*, 2.79.2)
2.79.2
22/10/2018
WP-DBManager < 2.72 – OS Command Injection
The WP-DBManager (aka Database Manager) plugin before 2.72 for WordPress allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) $backup['filepath'] (aka "Path to Backup:" field) or (2) $backup['mysqldumppath'] variable.
[*, 2.72)
2.72
13/10/2014
WP-DBManager < 2.72 – Command Injection
(1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.72 for WordPress place credentials on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
[*, 2.72)
2.72
13/10/2014
WP DB Manager < 2.7.2 – Arbitrary File Read
The "Sql Run Query" panel in WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote attackers to read arbitrary files by leveraging failure to sufficiently limit queries, as demonstrated by use of LOAD_FILE in an INSERT…
[*, 2.7.2)
2.7.2
13/10/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.