Show filters
977 Total Results
Displaying 131-140 of 977
Sort by:
Attacker Value
Unknown

CVE-2023-52262

Disclosure Date: December 30, 2023 (last updated January 10, 2024)
outdoorbits little-backup-box (aka Little Backup Box) before f39f91c allows remote attackers to execute arbitrary code because the PHP extract function is used for untrusted input.
Attacker Value
Unknown

CVE-2023-7002

Disclosure Date: December 23, 2023 (last updated December 29, 2023)
The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execute arbitrary commands on the host operating system.
Attacker Value
Unknown

CVE-2023-6972

Disclosure Date: December 23, 2023 (last updated December 29, 2023)
The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible.
Attacker Value
Unknown

CVE-2023-6971

Disclosure Date: December 23, 2023 (last updated December 29, 2023)
The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. NOTE: Successful exploitation of this vulnerability requires that the target server's php.ini is configured with 'allow_url_include' set to 'on'. This feature is deprecated as of PHP 7.4 and is disabled by default, but can still be explicitly enabled in later versions of PHP.
Attacker Value
Unknown

CVE-2023-5738

Disclosure Date: November 27, 2023 (last updated December 02, 2023)
The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2023-5737

Disclosure Date: November 27, 2023 (last updated December 02, 2023)
The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.
Attacker Value
Unknown

CVE-2023-32583

Disclosure Date: November 13, 2023 (last updated November 17, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Prashant Walke WP All Backup plugin <= 2.4.3 versions.
Attacker Value
Unknown

CVE-2023-47102

Disclosure Date: November 07, 2023 (last updated November 14, 2023)
UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid.
Attacker Value
Unknown

CVE-2023-45499

Disclosure Date: October 27, 2023 (last updated November 09, 2023)
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.
Attacker Value
Unknown

CVE-2023-45498

Disclosure Date: October 27, 2023 (last updated November 09, 2023)
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability.