CVE-2014-3848
iMember360 < 3.9.000 - Unauthenticated Database Credential Exposure via i4w_dbinfo Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-3848. PoCs published by Everett Griffiths.
AI-analyzed exploit summary The writeup details multiple vulnerabilities in the iMember360 WordPress plugin, including database credential disclosure, XSS, arbitrary user deletion, and arbitrary code execution via unescaped shell commands. It provides proof-of-concept parameters for exploitation but lacks executable code.
Description
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials via the i4w_dbinfo parameter.
Exploits (1)
The writeup details multiple vulnerabilities in the iMember360 WordPress plugin, including database credential disclosure, XSS, arbitrary user deletion, and arbitrary code execution via unescaped shell commands. It provides proof-of-concept parameters for exploitation but lacks executable code.