NVD

Id
35609  
Name
CVE-2014-8603  
Description
cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file name when creating a backup or vectors related to the (2) $_CONFIG[tarpath], (3) $exclude, (4) $_CONFIG["tarcompress"], (5) $_CONFIG["filename"], (6) $_CONFIG["exfile_tar"], (7) $_CONFIG[sqldump], (8) $_CONFIG["mysql_host"], (9) $_CONFIG["mysql_pass"], (10) $_CONFIG["mysql_user"], (11) $database_name, or (12) $sqlfile variable.  
Reject
 
CVSS Version
2  
CVSS Score
6.5  
Severity
Medium  
CVSS Base Score
6.5  
CVSS Impact Subscore
6.4  
CVSS Exploit Subscore
8  
CVSS Vector
(AV:N/AC:L/Au:S/C:P/I:P/A:P)  
Pub Date
2017-01-19  
Published
2015-06-10  
Modified Date
2015-06-11  
Seq
2014-8603  

Actions