4
CVSSv2

CVE-2014-8606

Published: 10/06/2015 Updated: 11/06/2015
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files via a .. (dot dot) in the file parameter in a json_return action in the xcloner_show page to wp-admin/admin-ajax.php.

Vulnerable Product Search on Vulmon Subscribe to Product

xcloner xcloner 3.1.1

xcloner xcloner 3.5.1

Exploits

Title: XCloner Wordpress/Joomla! backup Plugin v311 (Wordpress) v351 (Joomla!) Vulnerabilities Author: Larry W Cashdollar, @_larry0 Date: 10/17/2014 Download: wordpressorg/plugins/xcloner-backup-and-restore/ Download: extensionsjoomlaorg/extensions/access-a-security/site-security/backup/665 Downloads: Wordpress 313,647 Joomla ...