WordPress CM Download Manager Plugin CVE-2014-8877 Remote PHP Code Execution Vulnerability
BID:71204
Info
WordPress CM Download Manager Plugin CVE-2014-8877 Remote PHP Code Execution Vulnerability
| Bugtraq ID: | 71204 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8877 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 20 2014 12:00AM |
| Updated: | Nov 20 2014 12:00AM |
| Credit: | Phi Le Ngoc |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress CM Download Manager Plugin CVE-2014-8877 Remote PHP Code Execution Vulnerability
The CM Download Manager for WordPress is prone to remote PHP-code execution vulnerability because it fails to properly validate user-supplied input.
An attacker can exploit this issue to execute arbitrary PHP code within the context of the web server. This may lead to a full compromise of the affected application or aid in further attacks.
CM Download Manager 2.0.0 and prior are vulnerable.
The CM Download Manager for WordPress is prone to remote PHP-code execution vulnerability because it fails to properly validate user-supplied input.
An attacker can exploit this issue to execute arbitrary PHP code within the context of the web server. This may lead to a full compromise of the affected application or aid in further attacks.
CM Download Manager 2.0.0 and prior are vulnerable.
Exploit / POC
WordPress CM Download Manager Plugin CVE-2014-8877 Remote PHP Code Execution Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
References
WordPress CM Download Manager Plugin CVE-2014-8877 Remote PHP Code Execution Vulnerability
References:
References:
- CM Download Manager Homepage (CreativeMinds)
- CM Download Manager Pro Edition Changelog (CreativeMinds)
- CM Download Manager WordPress Page (WordPress)
- CVE-2014-8877 - Code Injection in Wordpress CM Download Manager plugin (Phi Le Ngoc)
- WordPress Homepage (WordPress)