CVE Vulnerabilities

CVE-2013-2742

Published: Apr 02, 2013 | Modified: Apr 02, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not reliably delete itself after completing a restore operation, which makes it easier for remote attackers to obtain access via subsequent requests to this script.

Affected Software

Name Vendor Start Version End Version
Backupbuddy Ithemes 1.3.4 (including) 1.3.4 (including)
Backupbuddy Ithemes 2.1.4 (including) 2.1.4 (including)
Backupbuddy Ithemes 2.2.4 (including) 2.2.4 (including)
Backupbuddy Ithemes 2.2.25 (including) 2.2.25 (including)
Backupbuddy Ithemes 2.2.28 (including) 2.2.28 (including)

References