Vulnonym.com

CVE-2006-5905 - Unconsenting Congress

Description

Web Directory Pro allows remote attackers to (1) backup the database and obtain the backup via a direct request to admin/backup_db.php or (2) modify configuration via a direct request to admin/options.php.

Reference

http://securityreason.com/securityalert/1859 http://secunia.com/advisories/35327 https://exchange.xforce.ibmcloud.com/vulnerabilities/30009 webdirectorypro-url-security-bypass(30009) https://www.exploit-db.com/exploits/8878 http://www.securityfocus.com/archive/1/450556/100/0/threaded