EasyCart <= 2.0.5 - Sensitive Information Disclosure
2014-05-28 00:00
Anant Shrivastava (anantshri)Strategic Overview
StatusPatched in 2.0.6
Affected PluginShopping Cart & eCommerce Store
Affected Version
<= 2.0.5CVSS5.3Medium
CVE
CVE-2014-4942Vulnerability Overview
The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information via a direct request to inc/admin/phpinfo.php, which calls the phpinfo function.
Technical Analysis
REMEDIATION: Update to version 2.0.6, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C