First published: Tue Jun 30 2015(Updated: )
Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Slider Revolution | <=4.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9734 has a medium severity rating due to its potential for unauthorized file access.
To fix CVE-2014-9734, update the Slider Revolution plugin to version 4.2 or later.
CVE-2014-9734 is a directory traversal vulnerability allowing file read access.
CVE-2014-9734 affects users of Slider Revolution plugin versions prior to 4.2 for WordPress.
Attackers can exploit CVE-2014-9734 to read arbitrary files on the server.