(1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress place credentials on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
References
Configurations
History
21 Nov 2024, 02:18
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/128785/WordPress-Database-Manager-2.7.1-Command-Injection-Credential-Leak.html - Exploit, Issue Tracking, Third Party Advisory, VDB Entry | |
References | () http://www.openwall.com/lists/oss-security/2014/10/20/7 - Mailing List | |
References | () http://www.vapid.dhs.org/advisories/wordpress/plugins/wp-dbmanager-2.7.1/index.html - Exploit, Third Party Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/97691 - VDB Entry | |
References | () https://github.com/lesterchan/wp-dbmanager/commit/7037fa8f61644098044379190d1d4bf1883b8e4a - Issue Tracking, Patch, Third Party Advisory | |
References | () https://wordpress.org/plugins/wp-dbmanager/#developers - Third Party Advisory |
Information
Published : 2018-01-05 16:29
Updated : 2024-11-21 02:18
NVD link : CVE-2014-8335
Mitre link : CVE-2014-8335
CVE.ORG link : CVE-2014-8335
JSON object : View
Products Affected
wp-dbmanager_project
- wp-dbmanager
CWE
CWE-255
Credentials Management Errors