CVE-2014-1907
VideoWhisper Live Streaming Integration <4.29.5 - Path Traversal
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-1907.
AI-analyzed exploit summary The document provides a detailed technical analysis of multiple vulnerabilities in VideoWhisper Live Streaming Integration, including arbitrary file upload, XSS, and path traversal. It includes proof-of-concept examples for exploitation but does not contain functional exploit code.
Description
Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_login.php or (2) delete arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_logout.php.
Exploits (1)
The document provides a detailed technical analysis of multiple vulnerabilities in VideoWhisper Live Streaming Integration, including arbitrary file upload, XSS, and path traversal. It includes proof-of-concept examples for exploitation but does not contain functional exploit code.