WordPress Advanced Access Manager Plugin CVE-2014-6059 Arbitrary File Overwrite Vulnerability
BID:69549
CVE-2014-6059 |Info
WordPress Advanced Access Manager Plugin CVE-2014-6059 Arbitrary File Overwrite Vulnerability
| Bugtraq ID: | 69549 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-6059 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2014 12:00AM |
| Updated: | Sep 03 2014 12:00AM |
| Credit: | Tom Adams of security.dxw.com |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress Advanced Access Manager Plugin CVE-2014-6059 Arbitrary File Overwrite Vulnerability
Advanced Access Manager plugin for WordPress is prone to a vulnerability that may allow attackers to overwrite arbitrary local files.
Successful exploits may allow an attacker to overwrite arbitrary local files and execute arbitrary code in the context of the user running the affected application.
Advanced Access Manager 2.8.2 is vulnerable; other versions may also be affected.
Advanced Access Manager plugin for WordPress is prone to a vulnerability that may allow attackers to overwrite arbitrary local files.
Successful exploits may allow an attacker to overwrite arbitrary local files and execute arbitrary code in the context of the user running the affected application.
Advanced Access Manager 2.8.2 is vulnerable; other versions may also be affected.
Exploit / POC
WordPress Advanced Access Manager Plugin CVE-2014-6059 Arbitrary File Overwrite Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.