CVE-2014-3848
published 2014-05-23CVE-2014-3848: The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials via the…
PriorityP345medium5CVSS 2.0
AVNACLAuNCPINAN
EXPLOIT
EPSS
9.15%
94.7th percentile
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials via the i4w_dbinfo parameter.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| imember360 | imember360 | <= 3.9.000 | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/126324/WordPress-iMember360is-3.9.001-XSS-Disclosure-Code-Execution.htmlhttp://releases.imember360.com/http://seclists.org/fulldisclosure/2014/Apr/265http://www.exploit-db.com/exploits/33076http://www.osvdb.org/106298http://packetstormsecurity.com/files/126324/WordPress-iMember360is-3.9.001-XSS-Disclosure-Code-Execution.htmlhttp://releases.imember360.com/http://seclists.org/fulldisclosure/2014/Apr/265http://www.exploit-db.com/exploits/33076http://www.osvdb.org/106298
2014-05-23
Published