5
CVSSv2

CVE-2014-8799

Published: 28/11/2014 Updated: 05/02/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin prior to 2.5.4 for WordPress allows remote malicious users to read arbitrary files via a .. (dot dot) in the src parameter to lib/dp_image.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dukapress dukapress

Exploits

# Exploit Title: DukaPress 252 Path Traversal # Date: 27-10-2014 # Exploit Author: Kacper Szurek - securityszurekpl # Software Link: downloadswordpressorg/plugin/dukapress252zip # Category: webapps # CVE: CVE-2014-8799 1 Description dp_img_resize() returns $_REQUEST['src'] if $_REQUEST['w'] and $_REQUEST['h'] doesn't e ...