CVE-2014-8606
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Directory Traversal
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files via a .. (dot dot) in the file parameter in a json_return action in the xcloner_show page to wp-admin/admin-ajax.php.
Vulnerabilidad de salto de directorio en el plugin XCloner 3.1.1 para WordPress y 3.5.1 para Joomla! permite a administradores remotos leer ficheros arbitrarios a través de un .. (punto punto) en el parámetro file en una acción json_return en la página xcloner_show en wp-admin/admin-ajax.php.
XCloner plugin version 3.1.1 for WordPress and 3.5.1 for Joomla! suffers from arbitrary command execution, MySQL password disclosure, database backups exposed, unauthenticated remote access, and various other vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-10-17 CVE Published
- 2014-11-04 CVE Reserved
- 2014-11-10 First Exploit
- 2024-08-06 CVE Updated
- 2024-10-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/35212 | 2014-11-10 | |
http://www.vapid.dhs.org/advisories/wordpress/plugins/Xcloner-v3.1.1 | 2024-08-06 | |
http://www.vapid.dhs.org/advisory.php?v=110 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xcloner Search vendor "Xcloner" | Xcloner Search vendor "Xcloner" for product "Xcloner" | 3.1.1 Search vendor "Xcloner" for product "Xcloner" and version "3.1.1" | wordpress |
Affected
| ||||||
Xcloner Search vendor "Xcloner" | Xcloner Search vendor "Xcloner" for product "Xcloner" | 3.5.1 Search vendor "Xcloner" for product "Xcloner" and version "3.5.1" | joomla\! |
Affected
|