Record summary

CVE-2014-5181 has a selected CVSS score of 5.0; EIP currently links 1 Nuclei template.

Description

Directory traversal vulnerability in lastfm-proxy.php in the Last.fm Rotation (lastfm-rotation) plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the snode parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMLast.fm Rotation 1.0 - Path TraversalCVSS 5

Directory traversal vulnerability in lastfm-proxy.php in the Last.fm Rotation (lastfm-rotation) plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the snode parameter.

Impact

Remote attackers can read arbitrary files on the server, potentially leading to information disclosure or further exploitation.

Remediation

Update to the latest version of the plugin or apply security patches to fix the vulnerability.

WeaknessesCWE-22
AuthorsDhiyaneshDK
Template tagswpscancvecve2014wp-cross-rsswordpresswp-pluginlfiwplastfm-rotationvuln
CVSS vector: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
CPE: cpe:2.3:a:last.fm_rotation_plugin_project:lastfm-rotation_plugin:1.0:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2