(1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress place credentials on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
                
            References
                    Configurations
                    History
                    21 Nov 2024, 02:18
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://packetstormsecurity.com/files/128785/WordPress-Database-Manager-2.7.1-Command-Injection-Credential-Leak.html - Exploit, Issue Tracking, Third Party Advisory, VDB Entry | |
| References | () http://www.openwall.com/lists/oss-security/2014/10/20/7 - Mailing List | |
| References | () http://www.vapid.dhs.org/advisories/wordpress/plugins/wp-dbmanager-2.7.1/index.html - Exploit, Third Party Advisory | |
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/97691 - VDB Entry | |
| References | () https://github.com/lesterchan/wp-dbmanager/commit/7037fa8f61644098044379190d1d4bf1883b8e4a - Issue Tracking, Patch, Third Party Advisory | |
| References | () https://wordpress.org/plugins/wp-dbmanager/#developers - Third Party Advisory | 
Information
                Published : 2018-01-05 16:29
Updated : 2024-11-21 02:18
NVD link : CVE-2014-8335
Mitre link : CVE-2014-8335
CVE.ORG link : CVE-2014-8335
JSON object : View
Products Affected
                wp-dbmanager_project
- wp-dbmanager
CWE
                
                    
                        
                        CWE-255
                        
            Credentials Management Errors
