CVE Vulnerabilities

CVE-2014-8585

Improper Link Resolution Before File Access ('Link Following')

Published: Nov 04, 2014 | Modified: May 05, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views/file_download.php or (2) file_download.php.

Weakness

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Affected Software

Name Vendor Start Version End Version
Wordpress_download_manager Wpdownloadmanager 1.1 (including) 1.1 (including)
Wordpress_download_manager Wpdownloadmanager 1.2 (including) 1.2 (including)
Wordpress_download_manager Wpdownloadmanager 1.2.1 (including) 1.2.1 (including)
Wordpress_download_manager Wpdownloadmanager 1.2.2 (including) 1.2.2 (including)
Wordpress_download_manager Wpdownloadmanager 1.2.3 (including) 1.2.3 (including)
Wordpress_download_manager Wpdownloadmanager 1.2.4 (including) 1.2.4 (including)
Wordpress_download_manager Wpdownloadmanager 1.2.5 (including) 1.2.5 (including)
Wordpress_download_manager Wpdownloadmanager 1.3 (including) 1.3 (including)
Wordpress_download_manager Wpdownloadmanager 1.4 (including) 1.4 (including)
Wordpress_download_manager Wpdownloadmanager 1.5 (including) 1.5 (including)
Wordpress_download_manager Wpdownloadmanager 1.5.1 (including) 1.5.1 (including)
Wordpress_download_manager Wpdownloadmanager 1.5.2 (including) 1.5.2 (including)
Wordpress_download_manager Wpdownloadmanager 1.5.3 (including) 1.5.3 (including)
Wordpress_download_manager Wpdownloadmanager 1.5.9 (including) 1.5.9 (including)
Wordpress_download_manager Wpdownloadmanager 1.5.32 (including) 1.5.32 (including)
Wordpress_download_manager Wpdownloadmanager 1.5.33 (including) 1.5.33 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.1 (including) 2.0.1 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.2 (including) 2.0.2 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.3 (including) 2.0.3 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.4 (including) 2.0.4 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.5 (including) 2.0.5 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.6 (including) 2.0.6 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.7 (including) 2.0.7 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.8 (including) 2.0.8 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.9 (including) 2.0.9 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.10 (including) 2.0.10 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.11 (including) 2.0.11 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.12 (including) 2.0.12 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.13 (including) 2.0.13 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.14 (including) 2.0.14 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.15 (including) 2.0.15 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.16 (including) 2.0.16 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.17 (including) 2.0.17 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.18 (including) 2.0.18 (including)
Wordpress_download_manager Wpdownloadmanager 2.0.19 (including) 2.0.19 (including)
Wordpress_download_manager Wpdownloadmanager 2.1.0 (including) 2.1.0 (including)
Wordpress_download_manager Wpdownloadmanager 2.1.1 (including) 2.1.1 (including)
Wordpress_download_manager Wpdownloadmanager 2.1.2 (including) 2.1.2 (including)
Wordpress_download_manager Wpdownloadmanager 2.1.3 (including) 2.1.3 (including)
Wordpress_download_manager Wpdownloadmanager 2.2.0 (including) 2.2.0 (including)
Wordpress_download_manager Wpdownloadmanager 2.2.1 (including) 2.2.1 (including)
Wordpress_download_manager Wpdownloadmanager 2.2.2 (including) 2.2.2 (including)
Wordpress_download_manager Wpdownloadmanager 2.2.3 (including) 2.2.3 (including)
Wordpress_download_manager Wpdownloadmanager 2.2.4 (including) 2.2.4 (including)
Wordpress_download_manager Wpdownloadmanager 2.2.5 (including) 2.2.5 (including)
Wordpress_download_manager Wpdownloadmanager 2.2.6 (including) 2.2.6 (including)
Wordpress_download_manager Wpdownloadmanager 2.2.7 (including) 2.2.7 (including)
Wordpress_download_manager Wpdownloadmanager 2.2.8 (including) 2.2.8 (including)
Wordpress_download_manager Wpdownloadmanager 2.2.9 (including) 2.2.9 (including)
Wordpress_download_manager Wpdownloadmanager 2.3.0 (including) 2.3.0 (including)
Wordpress_download_manager Wpdownloadmanager 2.3.1 (including) 2.3.1 (including)
Wordpress_download_manager Wpdownloadmanager 2.3.2 (including) 2.3.2 (including)
Wordpress_download_manager Wpdownloadmanager 2.3.3 (including) 2.3.3 (including)
Wordpress_download_manager Wpdownloadmanager 2.3.4 (including) 2.3.4 (including)
Wordpress_download_manager Wpdownloadmanager 2.3.5 (including) 2.3.5 (including)
Wordpress_download_manager Wpdownloadmanager 2.3.6 (including) 2.3.6 (including)
Wordpress_download_manager Wpdownloadmanager 2.3.7 (including) 2.3.7 (including)
Wordpress_download_manager Wpdownloadmanager 2.3.8 (including) 2.3.8 (including)
Wordpress_download_manager Wpdownloadmanager 2.3.9 (including) 2.3.9 (including)
Wordpress_download_manager Wpdownloadmanager 2.4.0 (including) 2.4.0 (including)
Wordpress_download_manager Wpdownloadmanager 2.4.1 (including) 2.4.1 (including)
Wordpress_download_manager Wpdownloadmanager 2.4.2 (including) 2.4.2 (including)
Wordpress_download_manager Wpdownloadmanager 2.4.3 (including) 2.4.3 (including)
Wordpress_download_manager Wpdownloadmanager 2.4.4 (including) 2.4.4 (including)
Wordpress_download_manager Wpdownloadmanager 2.4.5 (including) 2.4.5 (including)
Wordpress_download_manager Wpdownloadmanager 2.4.6 (including) 2.4.6 (including)
Wordpress_download_manager Wpdownloadmanager 2.4.7 (including) 2.4.7 (including)
Wordpress_download_manager Wpdownloadmanager 2.4.8 (including) 2.4.8 (including)
Wordpress_download_manager Wpdownloadmanager 2.4.9 (including) 2.4.9 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.0 (including) 2.5.0 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.1 (including) 2.5.1 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.2 (including) 2.5.2 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.3 (including) 2.5.3 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.4 (including) 2.5.4 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.5 (including) 2.5.5 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.6 (including) 2.5.6 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.7 (including) 2.5.7 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.8 (including) 2.5.8 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.9 (including) 2.5.9 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.91 (including) 2.5.91 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.92 (including) 2.5.92 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.93 (including) 2.5.93 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.94 (including) 2.5.94 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.95 (including) 2.5.95 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.96 (including) 2.5.96 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.97 (including) 2.5.97 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.98 (including) 2.5.98 (including)
Wordpress_download_manager Wpdownloadmanager 2.5.99 (including) 2.5.99 (including)
Wordpress_download_manager Wpdownloadmanager 2.6.0 (including) 2.6.0 (including)
Wordpress_download_manager Wpdownloadmanager 2.6.1 (including) 2.6.1 (including)
Wordpress_download_manager Wpdownloadmanager 2.6.2 (including) 2.6.2 (including)
Wordpress_download_manager Wpdownloadmanager 2.6.3 (including) 2.6.3 (including)
Wordpress_download_manager Wpdownloadmanager 2.6.4 (including) 2.6.4 (including)
Wordpress_download_manager Wpdownloadmanager 2.6.5 (including) 2.6.5 (including)
Wordpress_download_manager Wpdownloadmanager 2.6.6 (including) 2.6.6 (including)
Wordpress_download_manager Wpdownloadmanager 2.6.7 (including) 2.6.7 (including)
Wordpress_download_manager Wpdownloadmanager 2.6.8 (including) 2.6.8 (including)
Wordpress_download_manager Wpdownloadmanager 2.6.9 (including) 2.6.9 (including)
Wordpress_download_manager Wpdownloadmanager 2.6.91 (including) 2.6.91 (including)
Wordpress_download_manager Wpdownloadmanager 2.6.92 (including) 2.6.92 (including)
Wordpress_download_manager Wpdownloadmanager 2.6.93 (including) 2.6.93 (including)
Wordpress_download_manager Wpdownloadmanager 2.6.94 (including) 2.6.94 (including)
Wordpress_download_manager Wpdownloadmanager 2.6.95 (including) 2.6.95 (including)
Wordpress_download_manager Wpdownloadmanager 2.6.96 (including) 2.6.96 (including)

Potential Mitigations

  • Follow the principle of least privilege when assigning access rights to entities in a software system.
  • Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.

References