10
CVSSv2

CVE-2014-1905

Published: 29/12/2014 Updated: 30/12/2014
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin prior to 4.29.5 for WordPress allows remote malicious users to execute arbitrary PHP code by uploading a file with a double extension, and then accessing the file via a direct request to a wp-content/plugins/videowhisper-live-streaming-integration/ls/snapshots/ pathname, as demonstrated by a .php.jpg filename.

Vulnerable Product Search on Vulmon Subscribe to Product

videowhisper videowhisper live streaming integration

Exploits

Advisory ID: HTB23199 Product: VideoWhisper Live Streaming Integration Vendor: VideoWhisper Vulnerable Version(s): 4273 and probably prior Tested Version: 4273 Advisory Publication: February 6, 2014 [without technical details] Vendor Notification: February 6, 2014 Vendor Patch: February 7, 2014 Public Disclosure: February 27, 2014 Vulnerability ...
VideoWhisper Live Streaming Integration version 4273 suffers from cross site scripting, remote shell upload, information exposure, and path traversal vulnerabilities ...