5
CVSSv2

CVE-2014-1908

Published: 29/12/2014 Updated: 30/12/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugin prior to 4.29.5 for WordPress allows remote malicious users to obtain sensitive information via a direct request, which reveals the full path in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

videowhisper videowhisper live streaming integration

Exploits

Advisory ID: HTB23199 Product: VideoWhisper Live Streaming Integration Vendor: VideoWhisper Vulnerable Version(s): 4273 and probably prior Tested Version: 4273 Advisory Publication: February 6, 2014 [without technical details] Vendor Notification: February 6, 2014 Vendor Patch: February 7, 2014 Public Disclosure: February 27, 2014 Vulnerability ...
VideoWhisper Live Streaming Integration version 4273 suffers from cross site scripting, remote shell upload, information exposure, and path traversal vulnerabilities ...