CVE-2014-1907
Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a ..
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_login.php or (2) delete arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_logout.php.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
- EPSS
- 10.93% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- videowhisper/live streaming integration plugin · videowhisper/videowhisper live streaming integration
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/125454Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91478
- https://www.htbridge.com/advisory/HTB23199Exploit
- http://packetstormsecurity.com/files/125454Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91478
- https://www.htbridge.com/advisory/HTB23199Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.