5

CVE-2014-1908

Exploit

Broadcast Live Video – Live Streaming < 4.29.5 - Full Path Disclosure

The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.
Mögliche Gegenmaßnahme
Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP: Update to version 4.29.5, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP
Version [*, 4.29.5)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VideowhisperVideowhisper Live Streaming Integration SwPlatformwordpress Version <= 4.27.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.37% 0.9
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.