iMember360 3.8.012 - 3.9.001 - Remote Code Execution

2014-04-24 00:00
Everett Griffiths

Strategic Overview

Status
Patched in 3.9.002
Affected PluginiMember360is
Affected Version3.8.012 – 3.9.001
CVSS7.2High
CVECVE-2014-8949
View all iMember360is vulnerabilities

Vulnerability Overview

The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the i4w_trace parameter. NOTE: this can be leveraged with CVE-2014-8948 to allow remote attackers to execute code. NOTE: it is not clear whether this issue itself crosses privileges.

Technical Analysis

REMEDIATION: Update to version 3.9.002, or a newer patched version --- IDENTIFIER: CWE-94 (Improper Control of Generation of Code ('Code Injection')) The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C