CVE-2014-1907

VideoWhisper Live Streaming Integration <4.29.5 - Path Traversal

Title source: llm

Description

Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_login.php or (2) delete arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_logout.php.

Exploits (1)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/31986

Scores

EPSS 0.0801
EPSS Percentile 92.1%

Details

CWE
CWE-22
Status published
Products (11)
videowhisper/live_streaming_integration_plugin 4.27
videowhisper/live_streaming_integration_plugin 4.27.3
videowhisper/videowhisper_live_streaming_integration 1.0.2
videowhisper/videowhisper_live_streaming_integration 2.0
videowhisper/videowhisper_live_streaming_integration 2.1
videowhisper/videowhisper_live_streaming_integration 2.2
videowhisper/videowhisper_live_streaming_integration 4.05
videowhisper/videowhisper_live_streaming_integration 4.07
videowhisper/videowhisper_live_streaming_integration 4.25
videowhisper/videowhisper_live_streaming_integration 4.25.3
... and 1 more
Published Mar 06, 2014
Tracked Since Feb 18, 2026