CVE-2011-5208: Path Traversal
Multiple directory traversal vulnerabilities in the BackWPup plugin before 1.4.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the wpabs parameter to (1) app/options-viewlog-iframe.php or (2) app/options-runnow-iframe.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5208?
CVE-2011-5208 has a moderate severity level due to its potential for unauthorized file access.
How do I fix CVE-2011-5208?
To fix CVE-2011-5208, update the BackWPup plugin to version 1.4.1 or later.
What are the impacted components in CVE-2011-5208?
CVE-2011-5208 affects the BackWPup plugin versions prior to 1.4.1, specifically the options-view_log-iframe.php and options-runnow-iframe.php files.
Can CVE-2011-5208 allow remote code execution?
No, CVE-2011-5208 allows for file reading but does not provide a direct pathway for remote code execution.
Who is at risk from CVE-2011-5208?
WordPress users running vulnerable versions of the BackWPup plugin prior to 1.4.1 are at risk from CVE-2011-5208.