CVE-2014-8603

Vulnérabilités

CVE-2014-8603

cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla!

MEDIUM xcloner

cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file name when creating a backup or vectors related to the (2) $_CONFIG[tarpath], (3) $exclude, (4) $_CONFIG['tarcompress'], (5) $_CONFIG['filename'], (6) $_CONFIG['exfile_tar'], (7) $_CONFIG[sqldump], (8) $_CONFIG['mysql_host'], (9) $_CONFIG['mysql_pass'], (10) $_CONFIG['mysql_user'], (11) $database_name, or (12) $sqlfile variable.

6.5 Moyenne · CVSS 2.0

AV:N/AC:L/Au:S/C:P/I:P/A:P

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDMEDIUM 6.5 (v2.0)
Produit
xcloner
Corrigée dans
Non précisée
Publiée
10/06/2015
Modifiée
17/06/2026
CWE
CWE-20
  • xcloner — 3.1.1 – 3.1.1
  • xcloner — 3.5.1 – 3.5.1

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:34 UTC