[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-8949Date: (C)2014-11-24   (M)2023-12-22


The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the i4w_trace parameter. NOTE: this can be leveraged with CVE-2014-8948 to allow remote attackers to execute code. NOTE: it is not clear whether this issue itself crosses privileges.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.0
Exploit Score: 6.8
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: SINGLE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
OSVDB-106301
http://seclists.org/fulldisclosure/2014/Apr/265
EXPLOIT-DB-33076
SECUNIA-58094
http://packetstormsecurity.com/files/126324/WordPress-iMember360is-3.9.001-XSS-Disclosure-Code-Execution.html

CPE    5
cpe:/a:imember360:imember360:3.9.001::~~~wordpress~~
cpe:/a:imember360:imember360:3.8.013::~~~wordpress~~
cpe:/a:imember360:imember360:3.9.000::~~~wordpress~~
cpe:/a:imember360:imember360:3.8.014::~~~wordpress~~
...
CWE    1
CWE-94

© SecPod Technologies