Description
WordPress Plugin BackupBuddy is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin BackupBuddy version 2.2.28 is vulnerable; other versions may also be affected.
Remediation
Make sure that the file 'importbuddy.php' is removed from the root of the website
References
http://packetstormsecurity.com/files/120923/Backupbuddy-2.2.4-Sensitive-Data-Exposure.html
http://archives.neohapsis.com/archives/fulldisclosure/2013-03/0205.html
Related Vulnerabilities
Magento Improper Input Validation Vulnerability (CVE-2019-7885)
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1052)
MySQL CVE-2017-3331 Vulnerability (CVE-2017-3331)
MySQL CVE-2024-21050 Vulnerability (CVE-2024-21050)
WordPress Plugin BackUpWordPress Unspecified Vulnerability (3.12)