Quantcast
Channel: Info Disclosure Files ≈ Packet Storm
Viewing all articles
Browse latest Browse all 141

Wordpress BulletProof Security Backup Disclosure

$
0
0
The Wordpress plugin BulletProof Security, versions less than or equal to 5.1, suffers from an information disclosure vulnerability, in that the db_backup_log.txt is publicly accessible. If the backup functionality is being utilized, this file will disclose where the backup files can be downloaded. After downloading the backup file, it will be parsed to grab all user credentials.

Viewing all articles
Browse latest Browse all 141

Trending Articles