CVE-2014-8335
HIGH 7.8EPSS 0.5%
(1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress place credentials on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
- CVSS v3.0
- 7.8 HIGH
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 0.53% chance of exploitation in the next 30 days, 43th percentile
- Published
- 2018-01-05
- Updated
- 2024-08-06
Proof-of-concept exploits (2)
- http://packetstormsecurity.com/files/128785/WordPress-Database-Manager-2.7.1-Command-Inje…
- http://www.vapid.dhs.org/advisories/wordpress/plugins/wp-dbmanager-2.7.1/index.html