myeasybackup has backdoor equivalent security vulnerability
-
If you install myeasybackup 1.0.5.3 (16 December 2010), unauthenticated anonymous outsiders can
[details removed for obvious reasons]
and thereby run arbitary code of their choice. It looks like there are a host of similar holes in other parts of the code (meb_settings.php), but marginally more complex to exploit.
This code is either amateurish, or deliberately written to be exploitable (conditionally assigning values to $_POST?? What is that? It is either sloppy stupidity, or evil genius).
IMHO, avoid this software until it has had a proper security review.
Viewing 9 replies - 1 through 9 (of 9 total)
Viewing 9 replies - 1 through 9 (of 9 total)
- The topic ‘myeasybackup has backdoor equivalent security vulnerability’ is closed to new replies.