6.4
CVSSv2

CVE-2014-1907

Published: 06/03/2014 Updated: 29/08/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin prior to 4.29.5 for WordPress allow remote malicious users to (1) read arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_login.php or (2) delete arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_logout.php.

Vulnerable Product Search on Vulmon Subscribe to Product

videowhisper live_streaming_integration_plugin 4.27

videowhisper live_streaming_integration_plugin 4.27.3

videowhisper live_streaming_integration_plugin 2.1

videowhisper live_streaming_integration_plugin 2.0

videowhisper live_streaming_integration_plugin

videowhisper live_streaming_integration_plugin 4.25.3

videowhisper live_streaming_integration_plugin 1.0.2

videowhisper live_streaming_integration_plugin 4.05

videowhisper live_streaming_integration_plugin 2.2

videowhisper live_streaming_integration_plugin 4.25

videowhisper live_streaming_integration_plugin 4.07

Exploits

Advisory ID: HTB23199 Product: VideoWhisper Live Streaming Integration Vendor: VideoWhisper Vulnerable Version(s): 4273 and probably prior Tested Version: 4273 Advisory Publication: February 6, 2014 [without technical details] Vendor Notification: February 6, 2014 Vendor Patch: February 7, 2014 Public Disclosure: February 27, 2014 Vulnerability ...
VideoWhisper Live Streaming Integration version 4273 suffers from cross site scripting, remote shell upload, information exposure, and path traversal vulnerabilities ...