Lucene search

K
cve[email protected]CVE-2014-8334
HistoryOct 31, 2014 - 2:55 p.m.

CVE-2014-8334

2014-10-3114:55:10
CWE-78
web.nvd.nist.gov
28
cve-2014-8334
wp-dbmanager
database manager
wordpress
remote authenticated users
arbitrary commands
shell metacharacters

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.4 High

AI Score

Confidence

Low

0.012 Low

EPSS

Percentile

85.0%

The WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) $backup[‘filepath’] (aka “Path to Backup:” field) or (2) $backup[‘mysqldumppath’] variable.

Affected configurations

NVD
Node
wp-dbmanager_projectwp-dbmanagerRange2.71wordpress

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.4 High

AI Score

Confidence

Low

0.012 Low

EPSS

Percentile

85.0%