6
CVSSv2

CVE-2014-8949

Published: 16/11/2014 Updated: 18/11/2014
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

The iMember360 plugin 3.8.012 up to and including 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the i4w_trace parameter. NOTE: this can be leveraged with CVE-2014-8948 to allow remote malicious users to execute code. NOTE: it is not clear whether this issue itself crosses privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

imember360 imember360 3.8.014

imember360 imember360 3.9.001

imember360 imember360 3.8.012

imember360 imember360 3.8.013

imember360 imember360 3.9.000

Exploits

------------ BACKGROUND ------------ "iMember360is a WordPress plugin that will turn a normal WordPress site into a full featured membership site It includes all the protection controls you can imagine, yet driven by Infusionsoft's second-to-none CRM and e-commerce engine" -- imember360com/ This plugin is hailed by some as being one of t ...