CVE-2014-8603
cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla!
MEDIUM
xcloner
Description
cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file name when creating a backup or vectors related to the (2) $_CONFIG[tarpath], (3) $exclude, (4) $_CONFIG['tarcompress'], (5) $_CONFIG['filename'], (6) $_CONFIG['exfile_tar'], (7) $_CONFIG[sqldump], (8) $_CONFIG['mysql_host'], (9) $_CONFIG['mysql_pass'], (10) $_CONFIG['mysql_user'], (11) $database_name, or (12) $sqlfile variable.
Sévérité
6.5
Moyenne · CVSS 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:P
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | MEDIUM | 6.5 (v2.0) |
Produit et versions
- Produit
- xcloner
- Corrigée dans
- Non précisée
- Publiée
- 10/06/2015
- Modifiée
- 17/06/2026
- CWE
- CWE-20
Versions concernées
- xcloner — 3.1.1 – 3.1.1
- xcloner — 3.5.1 – 3.5.1
Sources
- NVD CVE-2014-8603 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC