← Back

CVE-2014-8877

nvd nist
Published: Dec 5, 2014Modified: May 6, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress allows remote attackers to execute arbitrary PHP code via the CMDsearch parameter to cmdownloads/, which is processed by the PHP create_function function.

Affected (4)

Cm Download Manager
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Creative Minds
Up to 2.0.3
Version 2.0.0
Version 2.0.1
Version 2.0.2

Timeline

No history available yet.