CVE-2014-1907

VideoWhisper Live Streaming Integration <4.29.5 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-1907.

AI-analyzed exploit summary The document provides a detailed technical analysis of multiple vulnerabilities in VideoWhisper Live Streaming Integration, including arbitrary file upload, XSS, and path traversal. It includes proof-of-concept examples for exploitation but does not contain functional exploit code.

Description

Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_login.php or (2) delete arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_logout.php.

Exploits (1)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/31986

The document provides a detailed technical analysis of multiple vulnerabilities in VideoWhisper Live Streaming Integration, including arbitrary file upload, XSS, and path traversal. It includes proof-of-concept examples for exploitation but does not contain functional exploit code.

Classification
Writeup 95%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: VideoWhisper Live Streaming Integration 4.27.3
No auth needed
Prerequisites: Access to the vulnerable plugin endpoints · Web server misconfiguration for file uploads
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/91478

Scores

EPSS 0.1084
EPSS Percentile 95.3%

Details

CWE
CWE-22
Status published
Products (11)
videowhisper/live_streaming_integration_plugin 4.27
videowhisper/live_streaming_integration_plugin 4.27.3
videowhisper/videowhisper_live_streaming_integration 1.0.2
videowhisper/videowhisper_live_streaming_integration 2.0
videowhisper/videowhisper_live_streaming_integration 2.1
videowhisper/videowhisper_live_streaming_integration 2.2
videowhisper/videowhisper_live_streaming_integration 4.05
videowhisper/videowhisper_live_streaming_integration 4.07
videowhisper/videowhisper_live_streaming_integration 4.25
videowhisper/videowhisper_live_streaming_integration 4.25.3
... and 1 more
Published Mar 06, 2014
Tracked Since Feb 18, 2026