peter bassill · operator
$ cve CVE-2014-8603 JSON

CVE-2014-8603 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 6.2% (pctl 93)

Patch early

A public exploit exists.

Description

cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file name when creating a backup or vectors related to the (2) $_CONFIG[tarpath], (3) $exclude, (4) $_CONFIG['tarcompress'], (5) $_CONFIG['filename'], (6) $_CONFIG['exfile_tar'], (7) $_CONFIG[sqldump], (8) $_CONFIG['mysql_host'], (9) $_CONFIG['mysql_pass'], (10) $_CONFIG['mysql_user'], (11) $database_name, or (12) $sqlfile variable.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS6.2% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2015-06-10
Last modified2026-06-17

Affected (1)

VendorProduct
xclonerxcloner

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD