Lucene search

K
cve[email protected]CVE-2014-8607
HistoryJun 10, 2015 - 6:59 p.m.

CVE-2014-8607

2015-06-1018:59:04
CWE-200
web.nvd.nist.gov
17
cve-2014-8607
xcloner
wordpress
joomla
mysql
security vulnerability
sensitive information disclosure
nvd

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

6.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command line, which allows local users to obtain sensitive information via the ps command.

Affected configurations

NVD
Node
xclonerxclonerMatch3.1.1wordpress
OR
xclonerxclonerMatch3.5.1joomla\!

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

6.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%