Looking for the vulnerability index of Invicti's legacy products?
WordPress Plugin WP-DBManager 'wp-config.php' Arbitrary File Download (2.60) - Vulnerability Database

WordPress Plugin WP-DBManager 'wp-config.php' Arbitrary File Download (2.60)

Description

WordPress Plugin WP-DBManager is prone to a vulnerability that lets attackers download arbitrary files because the application fails to sufficiently verify user-supplied input. An attacker can exploit this issue to download the 'wp-config.php' script. This may allow attacker to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin WP-DBManager version 2.60 is vulnerable; prior versions may also be affected.

Remediation

Update to plugin version 2.61 or latest

Related Vulnerabilities