漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
All-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Location Log File Write via Path Traversal
Vulnerability Description
The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its intended storage directory.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress All-in-One WP Migration and Backup 路径遍历漏洞
Vulnerability Description
WordPress All-in-One WP Migration and Backup是WordPress基金会的一款全方位网站迁移与备份组件。 WordPress All-in-One WP Migration and Backup 7.106之前版本存在路径遍历漏洞,该漏洞源于未正确清理用户提供的值就用于构建文件路径,可能导致未经身份验证的攻击者在预期存储目录之外的任意位置创建或追加日志文件。
CVSS Information
N/A
Vulnerability Type
N/A