CVE Vulnerabilities

CVE-2014-8749

Published: Dec 01, 2014 | Modified: Dec 01, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Server-side request forgery (SSRF) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to trigger outbound requests that authenticate to arbitrary databases via the dbhost parameter.

Affected Software

Name Vendor Start Version End Version
Bulletproof_security Ait-pro * .51 (including)

References