vendor:
CM Download Manager plugin
by:
Le Ngoc Phi
7,5
CVSS
HIGH
Code Injection
78
CWE
Product Name: CM Download Manager plugin
Affected Version From: 2.0.0
Affected Version To: 2.0.4
Patch Exists: YES
Related CWE: CVE-2014-8877
CPE: 2.3:a:wordpress:cm_download_manager_plugin:2.0.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
Code Injection in WordPress CM Download Manager plugin 2.0.0
The code injection vulnerability has been found and confirmed within the software as an anonymous user. A successful attack could allow an anonymous attacker gains full control of the application and the ability to use any operating system functions that are available to the scripting environment.
Mitigation:
Upgrade to version 2.0.4 or later