← Back

CVE-2014-8605

nvd nist
Published: Jun 10, 2015Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to a backup file in administrators/backups/.

Affected (2)

Products: Xcloner: Xcloner
1 product
Xcloner
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Xcloner
Version 3.1.1
Version 3.5.1

Related CWEs

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.