Record summary

CVE-2014-4940 has a selected CVSS score of 5.0; EIP currently links 2 catalogued exploits and 1 Nuclei template.

Description

Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the fn parameter to (1) charts/treemap.php or (2) charts/zoomabletreemap.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2
Nuclei templates
1

Proofs of concept

2

Catalogued exploits

ExploitDBWordPress Plugin Tera Charts (tera-charts) - '/charts/treemap.php?fn' Directory TraversalExploitDB exploitby Anant ShrivastavaNot analyzed1 file
ExploitDB

PoC details
ExploitDBWordPress Plugin Tera Charts (tera-charts) - '/charts/zoomabletreemap.php?fn' Directory TraversalExploitDB exploitby Anant ShrivastavaNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Plugin Tera Charts - Local File InclusionCVSS 5

Multiple local file inclusion vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the fn parameter to (1) charts/treemap.php or (2) charts/zoomabletreemap.php.

Impact

An attacker can exploit this vulnerability to read sensitive files on the server.

Remediation

Update to the latest version of the Tera Charts plugin to fix the local file inclusion vulnerability.

WeaknessesCWE-22
Authorsdaffainfo
Template tagscve2014cvewordpresswp-pluginlfitera_charts_plugin_projectvuln
CVSS vector: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
CPE: cpe:2.3:a:tera_charts_plugin_project:tera-charts:0.1:*:*:*:*:wordpress:*:*
Google: inurl:"/wp-content/plugins/tera-charts"

Source: ProjectDiscovery

References

3