106301vdb entry
http://osvdb.org/show/osvdb/106301 CVE-2014-8948
WordPress Plugin iMember360 3.8.012 < 3.9.001 - Multiple Vulnerabilities
Record summary
CVE-2014-8948 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Cross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote attackers to hijack the authentication of administrators for requests that with an unspecified impact via the i4w_trace parameter. NOTE: this can be leveraged with CVE-2014-8948 to execute arbitrary commands.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin iMember360 3.8.012 < 3.9.001 - Multiple VulnerabilitiesExploitDB exploitby Everett GriffithsNot analyzed1 file
References
6packetstormsecurity.com
http://packetstormsecurity.com/files/126324/WordPress-iMember360is-3.9.001-XSS-Disclosure-Code-Execution.html 20140424 Multiple Vulnerabilities in iMember360 (Wordpress plugin)mailing list
http://seclists.org/fulldisclosure/2014/Apr/265 58094Third-party advisory
http://secunia.com/advisories/58094 33076exploit
http://www.exploit-db.com/exploits/33076 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-8948