Vulnerability Description
Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to "PHPSESSID"; (3) changing the image parameter to an array; or (4) changing the image parameter to a string, which reveals the installation path in an error message.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pluck-Cms | Pluck | 4.7.2 |
Related Weaknesses (CWE)
References
- http://rossmarks.uk/portfolio.phpThird Party Advisory
- http://rossmarks.uk/whitepapers/pluck_cms_4.7.txtExploit
- http://rossmarks.uk/portfolio.phpThird Party Advisory
- http://rossmarks.uk/whitepapers/pluck_cms_4.7.txtExploit
FAQ
What is CVE-2014-8706?
CVE-2014-8706 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to "PHPSESSID"; (3) changing the image parameter to a...
How severe is CVE-2014-8706?
CVE-2014-8706 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-8706?
Check the references section above for vendor advisories and patch information. Affected products include: Pluck-Cms Pluck.