Description
WordPress Plugin BackupBuddy is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin BackupBuddy version 2.2.28 is vulnerable; other versions may also be affected.
Remediation
Make sure that the file 'importbuddy.php' is removed from the root of the website
References
http://packetstormsecurity.com/files/120923/Backupbuddy-2.2.4-Sensitive-Data-Exposure.html
http://archives.neohapsis.com/archives/fulldisclosure/2013-03/0205.html
Related Vulnerabilities
Jboss EAP Incorrect Authorization Vulnerability (CVE-2022-0866)
WordPress Plugin Import all XML, CSV & TXT into WordPress Security Bypass (6.4.1)
WordPress Plugin Theme Blvd Shortcodes Multiple Security Bypass Vulnerabilities (1.5.2)
TYPO3 Inadequate Encryption Strength Vulnerability (CVE-2010-3670)
WordPress Plugin VIDEO GALLERY 'upload1.php' Arbitrary File Upload (1.3)