CVE-2018-17207: Code Injection
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-17207?
The severity of CVE-2018-17207 is critical with a severity value of 9.8.
How does CVE-2018-17207 impact Snap Creek Duplicator?
CVE-2018-17207 allows an attacker to inject PHP code into wp-config.php during the database setup step, leading to arbitrary code execution.
How can an attacker exploit CVE-2018-17207?
An attacker can exploit CVE-2018-17207 by accessing leftover installer files (installer.php and installer-backup.php) and injecting PHP code during the database setup step.
Is there a fix available for CVE-2018-17207?
Yes, the fix for CVE-2018-17207 is available in Snap Creek Duplicator version 1.2.42.
Where can I find more information about CVE-2018-17207?
You can find more information about CVE-2018-17207 in the Snap Creek Duplicator documentation and the Synacktiv advisory.