CVE-2014-8607
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin <= 3.1.1 - Sensitive Information Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command line, which allows local users to obtain sensitive information via the ps command.
El plugin XCloner 3.1.1 para WordPress y 3.5.1 para Joomla! proporciona el nombre de usuario y la contraseña de MySQL en la línea de comando, lo que permite a usuarios locales obtener información sensible a través de el comando ps.
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command line, which allows local users with administrator privileges to obtain sensitive information via the ps command.
XCloner plugin version 3.1.1 for WordPress and 3.5.1 for Joomla! suffers from arbitrary command execution, MySQL password disclosure, database backups exposed, unauthenticated remote access, and various other vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-10-17 CVE Published
- 2014-11-04 CVE Reserved
- 2014-11-10 First Exploit
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/35212 | 2014-11-10 | |
http://www.vapid.dhs.org/advisories/wordpress/plugins/Xcloner-v3.1.1 | 2024-08-06 | |
http://www.vapid.dhs.org/advisory.php?v=110 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xcloner Search vendor "Xcloner" | Xcloner Search vendor "Xcloner" for product "Xcloner" | 3.1.1 Search vendor "Xcloner" for product "Xcloner" and version "3.1.1" | wordpress |
Affected
| ||||||
Xcloner Search vendor "Xcloner" | Xcloner Search vendor "Xcloner" for product "Xcloner" | 3.5.1 Search vendor "Xcloner" for product "Xcloner" and version "3.5.1" | joomla\! |
Affected
|