漏洞描述
Detects publicly accessible W3 Total Cache database cache files in the wp-content/w3tc/dbcache/ directory. When database caching to disk is enabled, these files contain raw SQL query results, potentially exposing sensitive data such as user details, password hashes, emails, or other database content if the directory is not properly protected.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.acunetix.comhttps://www.acunetix.com/vulnerabilities/web/wordpress-w3-total-cache-plugin-predictable-cache-filenames/↗www.openwall.comhttps://www.openwall.com/lists/oss-security/2012/12/30/3 (CVE-2012-6077 related discussion)↗siteground.comhttps://siteground.com/blog/w3-total-cache-vulnerability/↗