5
CVE-2014-8749
- EPSS 0.45%
- Veröffentlicht 01.12.2014 15:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
BulletProof Security < .51.1 - Server-Side Request Forgery
Server-side request forgery (SSRF) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to trigger outbound requests that authenticate to arbitrary databases via the dbhost parameter.
Mögliche Gegenmaßnahme
BulletProof Security: Update to version .51.1, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
BulletProof Security
Version
* - .51
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ait-pro ≫ Bulletproof Security SwPlatformwordpress Version <= .51
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.45% | 0.608 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|