Lucene search

K
cve[email protected]CVE-2014-8749
HistoryDec 01, 2014 - 3:59 p.m.

CVE-2014-8749

2014-12-0115:59:07
web.nvd.nist.gov
21
cve
ssrf
vulnerability
admin
htaccess
bps
plugin
wordpress
remote attackers
outbound requests
database authentication

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

7 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

67.9%

Server-side request forgery (SSRF) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to trigger outbound requests that authenticate to arbitrary databases via the dbhost parameter.

Affected configurations

NVD
Node
ait-probulletproof_securityRange.51wordpress

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

7 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

67.9%