CVE-2006-5705
published 2006-11-04CVE-2006-5705: Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in WordPress before 2.0.5 allow remote authenticated users to read or overwrite…
PriorityP427medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
3.43%
87.6th percentile
Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in WordPress before 2.0.5 allow remote authenticated users to read or overwrite arbitrary files via directory traversal sequences in the (1) backup and (2) fragment parameters in a GET request.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 2.0.5-0.1 (bookworm) | wordpress 2.0.5-0.1 (bookworm) |
| debian | wordpress | < wordpress 2.1.0-1 (bookworm) | wordpress 2.1.0-1 (bookworm) |
| wordpress | wordpress | <= 2.0.3 | — |
| wordpress | wordpress | <= 2.0.4 | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | >= 0 < 2.0.5-0.1 | 2.0.5-0.1 |
| wordpress | wordpress | >= 0 < 2.1.0-1 | 2.1.0-1 |
| wordpress | wordpress | >= 0 < 2.0.5-0.1 | 2.0.5-0.1 |
| wordpress | wordpress | >= 0 < 2.1.0-1 | 2.1.0-1 |
| wordpress | wordpress | >= 0 < 2.0.5-0.1 | 2.0.5-0.1 |
| wordpress | wordpress | >= 0 < 2.1.0-1 | 2.1.0-1 |
| wordpress | wordpress | >= 0 < 2.0.5-0.1 | 2.0.5-0.1 |
| wordpress | wordpress | >= 0 < 2.1.0-1 | 2.1.0-1 |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wjp2-fcqj-8w42: Directory traversal vulnerability in wp-db-backup
ghsa_unreviewed·2022-05-01·CVSS 6.0
CVE-2008-0194 [MEDIUM] CWE-22 GHSA-wjp2-fcqj-8w42: Directory traversal vulnerability in wp-db-backup
Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrary files, and cause a denial of service via a .. (dot dot) in the backup parameter in a wp-db-backup.php action to wp-admin/edit.php. NOTE: this might be the same as CVE-2006-5705.1.
GHSA
GHSA-fhp2-f8wf-wpqm: Multiple directory traversal vulnerabilities in plugins/wp-db-backup
ghsa_unreviewed·2022-05-01
CVE-2006-5705 [MEDIUM] GHSA-fhp2-f8wf-wpqm: Multiple directory traversal vulnerabilities in plugins/wp-db-backup
Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in WordPress before 2.0.5 allow remote authenticated users to read or overwrite arbitrary files via directory traversal sequences in the (1) backup and (2) fragment parameters in a GET request.
OSV
CVE-2008-0194: Directory traversal vulnerability in wp-db-backup
osv·2008-01-10·CVSS 6.0
CVE-2008-0194 [MEDIUM] CVE-2008-0194: Directory traversal vulnerability in wp-db-backup
Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrary files, and cause a denial of service via a .. (dot dot) in the backup parameter in a wp-db-backup.php action to wp-admin/edit.php. NOTE: this might be the same as CVE-2006-5705.1.
OSV
CVE-2006-5705: Multiple directory traversal vulnerabilities in plugins/wp-db-backup
osv·2006-11-04·CVSS 6.0
CVE-2006-5705 [MEDIUM] CVE-2006-5705: Multiple directory traversal vulnerabilities in plugins/wp-db-backup
Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in WordPress before 2.0.5 allow remote authenticated users to read or overwrite arbitrary files via directory traversal sequences in the (1) backup and (2) fragment parameters in a GET request.
Debian
CVE-2008-0194: wordpress - Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and ear...
vendor_debian·2008·CVSS 6.0
CVE-2008-0194 [MEDIUM] CVE-2008-0194: wordpress - Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and ear...
Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrary files, and cause a denial of service via a .. (dot dot) in the backup parameter in a wp-db-backup.php action to wp-admin/edit.php. NOTE: this might be the same as CVE-2006-5705.1.
Scope: local
bookworm: resolved (fixed in 2.1.0-1)
bullseye: resolved (fixed in 2.1.0-1)
forky: resolved (fixed in 2.1.0-1)
sid: resolved (fixed in 2.1.0-1)
trixie: resolved (fixed in 2.1.0-1)
Debian
CVE-2006-5705: wordpress - Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in Word...
vendor_debian·2006·CVSS 6.0
CVE-2006-5705 [MEDIUM] CVE-2006-5705: wordpress - Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in Word...
Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in WordPress before 2.0.5 allow remote authenticated users to read or overwrite arbitrary files via directory traversal sequences in the (1) backup and (2) fragment parameters in a GET request.
Scope: local
bookworm: resolved (fixed in 2.0.5-0.1)
bullseye: resolved (fixed in 2.0.5-0.1)
forky: resolved (fixed in 2.0.5-0.1)
sid: resolved (fixed in 2.0.5-0.1)
trixie: resolved (fixed in 2.0.5-0.1)
No detection rules found.
No public exploits indexed.
Bugzilla
vulnerable for DoS and info. leak
bugzilla·2006-12-27·CVSS 6.0
[MEDIUM] vulnerable for DoS and info. leak
vulnerable for DoS and info. leak
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.0.9) Gecko/20061219 Fedora/1.5.0.9-1.fc6 Firefox/1.5.0.9 pango-text
Description of problem:
Some vulnerabilities have been reported in Wordpress, which can be exploited by malicious users to gain knowledge of potentially sensitive information or cause a DoS (Denial of Service), and by malicious people to gain knowledge of sensitive information.
1) The /wp-admin/user-edit.php script does not correctly restrict access to the metadata of users. This can be exploited to list certain metadata information by passing the ID of a user in the "userid" parameter.
2) Input passed to various fields (e.g. the "first name" field in the profile page) is not properly sanitised before bein
Bugzilla
CVE-2006-5705: wordpress < 2.0.5 directory traversal vulnerability
bugzilla·2006-11-04·CVSS 6.0
CVE-2006-5705 [MEDIUM] CVE-2006-5705: wordpress < 2.0.5 directory traversal vulnerability
CVE-2006-5705: wordpress < 2.0.5 directory traversal vulnerability
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-5705
"Directory traversal vulnerability in plugins/wp-db-backup.php in WordPress
before 2.0.5 allows remote attackers to read arbitrary files via directory
traversal sequences in unspecified parameters related to the backup of fragment
files."
Based on the version number, all FE releases are affected.
Discussion:
*** Bug 216186 has been marked as a duplicate of this bug. ***
---
ping
---
Patches FC-[456], updated devel to 2.0.5
http://bugs.gentoo.org/show_bug.cgi?id=153303http://markjaquith.wordpress.com/2006/10/17/changes-in-wordpress-205/http://secunia.com/advisories/22683http://secunia.com/advisories/22942http://trac.wordpress.org/changeset/4226http://wordpress.org/development/2006/10/205-ronan/http://www.gentoo.org/security/en/glsa/glsa-200611-10.xmlhttp://www.openpkg.org/security/advisories/OpenPKG-SA-2006.027-wordpress.htmlhttp://www.securityfocus.com/bid/20869http://www.vupen.com/english/advisories/2006/4307http://bugs.gentoo.org/show_bug.cgi?id=153303http://markjaquith.wordpress.com/2006/10/17/changes-in-wordpress-205/http://secunia.com/advisories/22683http://secunia.com/advisories/22942http://trac.wordpress.org/changeset/4226http://wordpress.org/development/2006/10/205-ronan/http://www.gentoo.org/security/en/glsa/glsa-200611-10.xmlhttp://www.openpkg.org/security/advisories/OpenPKG-SA-2006.027-wordpress.htmlhttp://www.securityfocus.com/bid/20869http://www.vupen.com/english/advisories/2006/4307
2006-11-04
Published