cleantalk
Vulnerabilities and Security Researches

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin, CVE-2014-8603

CVE, Research URL

CVE-2014-8603

Published on
Jun 10, 2015
Research Description
cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file name when creating a backup or vectors related to the (2) $_CONFIG[tarpath], (3) $exclude, (4) $_CONFIG['tarcompress'], (5) $_CONFIG['filename'], (6) $_CONFIG['exfile_tar'], (7) $_CONFIG[sqldump], (8) $_CONFIG['mysql_host'], (9) $_CONFIG['mysql_pass'], (10) $_CONFIG['mysql_user'], (11) $database_name, or (12) $sqlfile variable.
Affected versions
Min -, max 3.1.2.
Status
vulnerable