CVE Vulnerabilities

CVE-2014-8585

Improper Link Resolution Before File Access ('Link Following')

Published: Nov 04, 2014 | Modified: May 05, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views/file_download.php or (2) file_download.php.

Weakness

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Affected Software

Name Vendor Start Version End Version
Wordpress_download_manager Wpdownloadmanager 1.1 1.1
Wordpress_download_manager Wpdownloadmanager 1.2 1.2
Wordpress_download_manager Wpdownloadmanager 1.2.1 1.2.1
Wordpress_download_manager Wpdownloadmanager 1.2.2 1.2.2
Wordpress_download_manager Wpdownloadmanager 1.2.3 1.2.3
Wordpress_download_manager Wpdownloadmanager 1.2.4 1.2.4
Wordpress_download_manager Wpdownloadmanager 1.2.5 1.2.5
Wordpress_download_manager Wpdownloadmanager 1.3 1.3
Wordpress_download_manager Wpdownloadmanager 1.4 1.4
Wordpress_download_manager Wpdownloadmanager 1.5 1.5
Wordpress_download_manager Wpdownloadmanager 1.5.1 1.5.1
Wordpress_download_manager Wpdownloadmanager 1.5.2 1.5.2
Wordpress_download_manager Wpdownloadmanager 1.5.3 1.5.3
Wordpress_download_manager Wpdownloadmanager 1.5.9 1.5.9
Wordpress_download_manager Wpdownloadmanager 1.5.32 1.5.32
Wordpress_download_manager Wpdownloadmanager 1.5.33 1.5.33
Wordpress_download_manager Wpdownloadmanager 2.0.1 2.0.1
Wordpress_download_manager Wpdownloadmanager 2.0.2 2.0.2
Wordpress_download_manager Wpdownloadmanager 2.0.3 2.0.3
Wordpress_download_manager Wpdownloadmanager 2.0.4 2.0.4
Wordpress_download_manager Wpdownloadmanager 2.0.5 2.0.5
Wordpress_download_manager Wpdownloadmanager 2.0.6 2.0.6
Wordpress_download_manager Wpdownloadmanager 2.0.7 2.0.7
Wordpress_download_manager Wpdownloadmanager 2.0.8 2.0.8
Wordpress_download_manager Wpdownloadmanager 2.0.9 2.0.9
Wordpress_download_manager Wpdownloadmanager 2.0.10 2.0.10
Wordpress_download_manager Wpdownloadmanager 2.0.11 2.0.11
Wordpress_download_manager Wpdownloadmanager 2.0.12 2.0.12
Wordpress_download_manager Wpdownloadmanager 2.0.13 2.0.13
Wordpress_download_manager Wpdownloadmanager 2.0.14 2.0.14
Wordpress_download_manager Wpdownloadmanager 2.0.15 2.0.15
Wordpress_download_manager Wpdownloadmanager 2.0.16 2.0.16
Wordpress_download_manager Wpdownloadmanager 2.0.17 2.0.17
Wordpress_download_manager Wpdownloadmanager 2.0.18 2.0.18
Wordpress_download_manager Wpdownloadmanager 2.0.19 2.0.19
Wordpress_download_manager Wpdownloadmanager 2.1.0 2.1.0
Wordpress_download_manager Wpdownloadmanager 2.1.1 2.1.1
Wordpress_download_manager Wpdownloadmanager 2.1.2 2.1.2
Wordpress_download_manager Wpdownloadmanager 2.1.3 2.1.3
Wordpress_download_manager Wpdownloadmanager 2.2.0 2.2.0
Wordpress_download_manager Wpdownloadmanager 2.2.1 2.2.1
Wordpress_download_manager Wpdownloadmanager 2.2.2 2.2.2
Wordpress_download_manager Wpdownloadmanager 2.2.3 2.2.3
Wordpress_download_manager Wpdownloadmanager 2.2.4 2.2.4
Wordpress_download_manager Wpdownloadmanager 2.2.5 2.2.5
Wordpress_download_manager Wpdownloadmanager 2.2.6 2.2.6
Wordpress_download_manager Wpdownloadmanager 2.2.7 2.2.7
Wordpress_download_manager Wpdownloadmanager 2.2.8 2.2.8
Wordpress_download_manager Wpdownloadmanager 2.2.9 2.2.9
Wordpress_download_manager Wpdownloadmanager 2.3.0 2.3.0
Wordpress_download_manager Wpdownloadmanager 2.3.1 2.3.1
Wordpress_download_manager Wpdownloadmanager 2.3.2 2.3.2
Wordpress_download_manager Wpdownloadmanager 2.3.3 2.3.3
Wordpress_download_manager Wpdownloadmanager 2.3.4 2.3.4
Wordpress_download_manager Wpdownloadmanager 2.3.5 2.3.5
Wordpress_download_manager Wpdownloadmanager 2.3.6 2.3.6
Wordpress_download_manager Wpdownloadmanager 2.3.7 2.3.7
Wordpress_download_manager Wpdownloadmanager 2.3.8 2.3.8
Wordpress_download_manager Wpdownloadmanager 2.3.9 2.3.9
Wordpress_download_manager Wpdownloadmanager 2.4.0 2.4.0
Wordpress_download_manager Wpdownloadmanager 2.4.1 2.4.1
Wordpress_download_manager Wpdownloadmanager 2.4.2 2.4.2
Wordpress_download_manager Wpdownloadmanager 2.4.3 2.4.3
Wordpress_download_manager Wpdownloadmanager 2.4.4 2.4.4
Wordpress_download_manager Wpdownloadmanager 2.4.5 2.4.5
Wordpress_download_manager Wpdownloadmanager 2.4.6 2.4.6
Wordpress_download_manager Wpdownloadmanager 2.4.7 2.4.7
Wordpress_download_manager Wpdownloadmanager 2.4.8 2.4.8
Wordpress_download_manager Wpdownloadmanager 2.4.9 2.4.9
Wordpress_download_manager Wpdownloadmanager 2.5.0 2.5.0
Wordpress_download_manager Wpdownloadmanager 2.5.1 2.5.1
Wordpress_download_manager Wpdownloadmanager 2.5.2 2.5.2
Wordpress_download_manager Wpdownloadmanager 2.5.3 2.5.3
Wordpress_download_manager Wpdownloadmanager 2.5.4 2.5.4
Wordpress_download_manager Wpdownloadmanager 2.5.5 2.5.5
Wordpress_download_manager Wpdownloadmanager 2.5.6 2.5.6
Wordpress_download_manager Wpdownloadmanager 2.5.7 2.5.7
Wordpress_download_manager Wpdownloadmanager 2.5.8 2.5.8
Wordpress_download_manager Wpdownloadmanager 2.5.9 2.5.9
Wordpress_download_manager Wpdownloadmanager 2.5.91 2.5.91
Wordpress_download_manager Wpdownloadmanager 2.5.92 2.5.92
Wordpress_download_manager Wpdownloadmanager 2.5.93 2.5.93
Wordpress_download_manager Wpdownloadmanager 2.5.94 2.5.94
Wordpress_download_manager Wpdownloadmanager 2.5.95 2.5.95
Wordpress_download_manager Wpdownloadmanager 2.5.96 2.5.96
Wordpress_download_manager Wpdownloadmanager 2.5.97 2.5.97
Wordpress_download_manager Wpdownloadmanager 2.5.98 2.5.98
Wordpress_download_manager Wpdownloadmanager 2.5.99 2.5.99
Wordpress_download_manager Wpdownloadmanager 2.6.0 2.6.0
Wordpress_download_manager Wpdownloadmanager 2.6.1 2.6.1
Wordpress_download_manager Wpdownloadmanager 2.6.2 2.6.2
Wordpress_download_manager Wpdownloadmanager 2.6.3 2.6.3
Wordpress_download_manager Wpdownloadmanager 2.6.4 2.6.4
Wordpress_download_manager Wpdownloadmanager 2.6.5 2.6.5
Wordpress_download_manager Wpdownloadmanager 2.6.6 2.6.6
Wordpress_download_manager Wpdownloadmanager 2.6.7 2.6.7
Wordpress_download_manager Wpdownloadmanager 2.6.8 2.6.8
Wordpress_download_manager Wpdownloadmanager 2.6.9 2.6.9
Wordpress_download_manager Wpdownloadmanager 2.6.91 2.6.91
Wordpress_download_manager Wpdownloadmanager 2.6.92 2.6.92
Wordpress_download_manager Wpdownloadmanager 2.6.93 2.6.93
Wordpress_download_manager Wpdownloadmanager 2.6.94 2.6.94
Wordpress_download_manager Wpdownloadmanager 2.6.95 2.6.95
Wordpress_download_manager Wpdownloadmanager 2.6.96 2.6.96

Potential Mitigations

  • Follow the principle of least privilege when assigning access rights to entities in a software system.
  • Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.

References