WordPress Total Upkeep...

- AV AC AU C I A
发布: 2024-09-01
修订: 2024-10-05

This Metasploit module exploits an unauthenticated database backup vulnerability in WordPress plugin Boldgrid-Backup also known as Total Upkeep version < 1.14.10. First, env-info.php is read to get server information. Next, restore-info.json is read to retrieve the last backup file. That backup is then downloaded, and any sql files will be parsed looking for the wp_users INSERT statement to grab user creds.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息