Web Directory Pro allows remote attackers to (1) backup the database and obtain the backup via a direct request to admin/backup_db.php or (2) modify configuration via a direct request to admin/options.php.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/30009 | vdb entry |
https://www.exploit-db.com/exploits/8878 | exploit |
http://securityreason.com/securityalert/1859 | third party advisory |
http://secunia.com/advisories/35327 | third party advisory |
http://www.securityfocus.com/archive/1/450556/100/0/threaded | mailing list |