CVE-2013-2744: Infoleak
Published Apr 2, 2013
·Updated
importbuddy.php in the BackupBuddy plugin 2.2.25 for WordPress allows remote attackers to obtain configuration information via a step 0 phpinfo action, which calls the phpinfo function.
Affected Software
2 affected components
iThemes Backupbuddy=2.2.25
WordPress WordPress
Event History
Apr 2, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2744?
CVE-2013-2744 has a medium severity rating due to its potential for exposure of sensitive configuration information.
2
How do I fix CVE-2013-2744?
To fix CVE-2013-2744, update the BackupBuddy plugin to a version later than 2.2.25.
3
What is the impact of CVE-2013-2744?
The impact of CVE-2013-2744 is that it allows remote attackers to access sensitive server configuration details.
4
Which version of BackupBuddy is affected by CVE-2013-2744?
BackupBuddy version 2.2.25 is the only version affected by CVE-2013-2744.
5
Is WordPress itself affected by CVE-2013-2744?
No, WordPress itself is not affected by CVE-2013-2744; the vulnerability lies solely within BackupBuddy version 2.2.25.