CVE-2014-8877
The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress allows remote attackers to execute arbitrary PHP code via the CMDsearch parameter to cmdownloads/, which is processed by the PHP create_function function.
- Affected products
- Cm Download Manager
- Creative Minds Cm Download Manager
- ≤ 2.0.3, 2.0.0, 2.0.1, 2.0.2
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 14.4% (96th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2014-12-05
CVE-2014-8877 at NVD
5 known exploits for CVE-2014-8877
Proof-of-concept code and exploit modules indexed by Sploitus