Record summary

CVE-2014-5187 has a selected CVSS score of 5.0; EIP currently links 1 Nuclei template.

Description

Directory traversal vulnerability in the Tom M8te (tom-m8te) plugin 1.5.3 for WordPress allows remote attackers to read arbitrary files via the file parameter to tom-download-file.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMTom M8te (tom-m8te) Plugin 1.5.3 - Directory TraversalCVSS 5

Directory traversal vulnerability in the Tom M8te (tom-m8te) plugin 1.5.3 for WordPress allows remote attackers to read arbitrary files via the file parameter to tom-download-file.php.

Impact

Remote attackers can read arbitrary files on the server, potentially leading to information disclosure or further exploitation.

Remediation

Update to the latest version of the plugin or apply security patches to fix the vulnerability.

WeaknessesCWE-22
AuthorsDhiyaneshDK
Template tagswpscancvecve2014wp-cross-rsswordpresswp-pluginlfiwptom-m8tevuln
CVSS vector: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
CPE: cpe:2.3:a:tom_m8te_plugin_project:tom-m8te_plugin:1.5.3:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2