6

CVE-2014-8949

Exploit

iMember360 3.8.012 - 3.9.001 - Remote Code Execution

The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the i4w_trace parameter.  NOTE: this can be leveraged with CVE-2014-8948 to allow remote attackers to execute code.  NOTE: it is not clear whether this issue itself crosses privileges.
Mögliche Gegenmaßnahme
iMember360is: Update to version 3.9.002, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Imember360 ≫ Imember360 Version 3.8.012 SwPlatform wordpress
Imember360 ≫ Imember360 Version 3.8.013 SwPlatform wordpress
Imember360 ≫ Imember360 Version 3.8.014 SwPlatform wordpress
Imember360 ≫ Imember360 Version 3.9.000 SwPlatform wordpress
Imember360 ≫ Imember360 Version 3.9.001 SwPlatform wordpress
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt iMember360is
Version 3.8.012-3.9.001
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.51% 0.937
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://packetstormsecurity.com/files/126324/WordPress-iMember360is-3.9.001-XSS-Disclosure-Code-Execution.html
Exploit
http://seclists.org/fulldisclosure/2014/Apr/265
Exploit
http://secunia.com/advisories/58094
http://www.exploit-db.com/exploits/33076
Exploit
http://osvdb.org/show/osvdb/106301
https://www.wordfence.com/threat-intel/vulnerabilities/id/509097ae-5b20-4e91-9d82-cc6e3b64e518
Third Party Advisory