Make WordPress Core

Opened 13 years ago

Closed 13 years ago

Last modified 13 years ago

#25081 closed defect (bug) (invalid)

wordpress Bug / Vulnerability

Reported by: mohanpendyala Owned by:
Priority: normal Milestone:
Component: Filesystem API Version:
Severity: major Keywords:
Cc: Focuses:

Description

Vulnerable Path: wp-content/uploads/dump.sql

Google Dorks:
inurl:uploads"dump.sql"wordpress

inurl:wp-content/uploads/dump.sql

This vulnerable path revealing important data which contains Database info, Users emails, password hashes, registered emails and more sensitive data

Change History (3)

#1 @rmccue
13 years ago

Firstly, security issues should be reported via the correct private channels.

Secondly, this is not something that WordPress has included in the core code, this is probably from plugins.

#2 @rmccue
13 years ago

  • Milestone Awaiting Review
  • Resolutioninvalid
  • Status newclosed

#3 @SergeyBiryukov
13 years ago

  • Keywords needs-testing removed
Note: See TracTickets for help on using tickets.