Vulnerability Details CVE-2014-8799
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter to lib/dp_image.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.881
EPSS Ranking 99.5%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2014-8799
-
cpe:2.3:a:dukapress:dukapress:1.0
-
cpe:2.3:a:dukapress:dukapress:1.0.1
-
cpe:2.3:a:dukapress:dukapress:1.2.0
-
cpe:2.3:a:dukapress:dukapress:1.2.1
-
cpe:2.3:a:dukapress:dukapress:1.3.0
-
cpe:2.3:a:dukapress:dukapress:1.3.1
-
cpe:2.3:a:dukapress:dukapress:1.3.2
-
cpe:2.3:a:dukapress:dukapress:1.3.2.1
-
cpe:2.3:a:dukapress:dukapress:2.0
-
cpe:2.3:a:dukapress:dukapress:2.1
-
cpe:2.3:a:dukapress:dukapress:2.2
-
cpe:2.3:a:dukapress:dukapress:2.3
-
cpe:2.3:a:dukapress:dukapress:2.3.1
-
cpe:2.3:a:dukapress:dukapress:2.3.2
-
cpe:2.3:a:dukapress:dukapress:2.3.3
-
cpe:2.3:a:dukapress:dukapress:2.3.4
-
cpe:2.3:a:dukapress:dukapress:2.3.5
-
cpe:2.3:a:dukapress:dukapress:2.3.6
-
cpe:2.3:a:dukapress:dukapress:2.3.7
-
cpe:2.3:a:dukapress:dukapress:2.3.8
-
cpe:2.3:a:dukapress:dukapress:2.4
-
cpe:2.3:a:dukapress:dukapress:2.5
-
cpe:2.3:a:dukapress:dukapress:2.5.1
-
cpe:2.3:a:dukapress:dukapress:2.5.2
-
cpe:2.3:a:dukapress:dukapress:2.5.3