CVE-2014-4940
WordPress Plugin Tera Charts (tera-charts) - '/charts/treemap.php?fn' Directory Traversal
Record summary
CVE-2014-4940 has a selected CVSS score of 5.0; EIP currently links 2 catalogued exploits and 1 Nuclei template.
Description
Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the fn parameter to (1) charts/treemap.php or (2) charts/zoomabletreemap.php.
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBWordPress Plugin Tera Charts (tera-charts) - '/charts/treemap.php?fn' Directory TraversalExploitDB exploitby Anant ShrivastavaNot analyzed1 file
ExploitDBWordPress Plugin Tera Charts (tera-charts) - '/charts/zoomabletreemap.php?fn' Directory TraversalExploitDB exploitby Anant ShrivastavaNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Plugin Tera Charts - Local File InclusionCVSS 5
Multiple local file inclusion vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the fn parameter to (1) charts/treemap.php or (2) charts/zoomabletreemap.php.
Impact
An attacker can exploit this vulnerability to read sensitive files on the server.
Remediation
Update to the latest version of the Tera Charts plugin to fix the local file inclusion vulnerability.
Source: ProjectDiscovery