Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2014-8799

EPSS 91.13% · P100
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2014-8799

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter to lib/dp_image.php.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Wordpress DukaPress插件路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台,该平台支持在PHP和MySQL的服务器上架设个人博客网站。DukaPress是其中的一个用于创建网上商店的插件。 WordPress DukaPress插件2.5.3及之前版本的php/dp-functions.php脚本中‘dp_img_resize’函数存在目录遍历漏洞,该漏洞源于lib/dp_image.php脚本没有充分过滤‘src’参数。远程攻击者可借助目录遍历字符‘..’利用该漏洞读取任意文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2014-8799

#POC DescriptionSource LinkShenlong Link
1A directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter to lib/dp_image.php.https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2014/CVE-2014-8799.yamlPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2014-8799

登录查看更多情报信息。

Same Patch Batch · n/a · 2014-11-28 · 16 CVEs total

CVE-2014-7178Enalean Tuleap 输入验证漏洞
CVE-2014-7850Red Hat FreeIPA 跨站脚本漏洞
CVE-2014-8423Arris VAP2500 代码注入漏洞
CVE-2014-8424Arris VAP2500 授权问题漏洞
CVE-2014-8425Arris VAP2500 远程信息泄露漏洞
CVE-2014-8429Xavoc xEpan CMS 跨站请求伪造漏洞
CVE-2014-8801WordPress Paid Memberships Pro插件路径遍历漏洞
CVE-2014-8994Nagios和Icinga check_diskio插件符号链接漏洞
CVE-2014-9089MantisBT‘view_all_set.php’SQL注入漏洞
CVE-2014-3407Cisco Adaptive Security Appliance Software 资源管理错误漏洞
CVE-2014-4829多款IBM Security QRadar产品跨站请求伪造漏洞
CVE-2014-4831多款IBM Security QRadar产品授权问题漏洞
CVE-2014-4832多款IBM Security QRadar产品信息泄露漏洞
CVE-2014-4883uIP和lwIP DNS解析器DNS安全漏洞
CVE-2014-6075多款IBM Security QRadar产品信息泄露漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2014-8799

No comments yet


Leave a comment