849 B
849 B
CVE-2011-4342
Description
PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpabs parameter.
POC
Reference
- http://seclists.org/fulldisclosure/2011/Mar/328
- http://www.exploit-db.com/exploits/17056
- http://www.openwall.com/lists/oss-security/2011/11/22/10
- http://www.openwall.com/lists/oss-security/2011/11/22/7