CVE-2014-1907: Path Traversal
Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the s parameter to ls/rtmplogin.php or (2) delete arbitrary files via a .. (dot dot) in the s parameter to ls/rtmplogout.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1907?
CVE-2014-1907 has a moderate severity level due to its directory traversal vulnerabilities that allow file access and deletion.
How do I fix CVE-2014-1907?
To fix CVE-2014-1907, update the VideoWhisper Live Streaming Integration plugin to version 4.29.5 or later.
What versions of VideoWhisper Live Streaming Integration are affected by CVE-2014-1907?
CVE-2014-1907 affects VideoWhisper Live Streaming Integration plugin versions prior to 4.29.5, including versions 1.0.2, 2.0, 2.1, 2.2, 4.05, 4.07, 4.25, 4.25.3, and 4.27.
Can CVE-2014-1907 be exploited remotely?
Yes, CVE-2014-1907 can be exploited remotely by attackers with crafted requests allowing file reading and deletion.
What type of attacks can CVE-2014-1907 enable?
CVE-2014-1907 enables directory traversal attacks that can lead to unauthorized file access and potential denial of service through file deletion.