VYPR

XCloner

by Joomla

CVEs (3)

  • CVE-2014-8605Jun 10, 2015
    risk 0.04cvss epss 0.07

    The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to a backup file in…

  • CVE-2014-8604Jun 10, 2015
    risk 0.04cvss epss 0.07

    The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which allows remote attackers to obtain sensitive information via unspecified vectors.

  • CVE-2014-8606Jun 10, 2015
    risk 0.03cvss epss 0.06

    Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files via a .. (dot dot) in the file parameter in a json_return action in the xcloner_show page to wp-admin/admin-ajax.php.