Lucene search

K
cve[email protected]CVE-2014-8605
HistoryJun 10, 2015 - 6:59 p.m.

CVE-2014-8605

2015-06-1018:59:02
CWE-264
web.nvd.nist.gov
17
cve-2014-8605
xcloner
wordpress
joomla
database backup
predictable names
web security
access control
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

80.6%

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to a backup file in administrators/backups/.

Affected configurations

NVD
Node
xclonerxclonerMatch3.1.1wordpress
OR
xclonerxclonerMatch3.5.1joomla\!

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

80.6%