Server-side request forgery (SSRF) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to trigger outbound requests that authenticate to arbitrary databases via the dbhost parameter.
Advisories
Source ID Title
EUVD EUVD EUVD-2014-8580 Server-side request forgery (SSRF) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to trigger outbound requests that authenticate to arbitrary databases via the dbhost parameter.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T13:26:02.503Z

Reserved: 2014-10-13T00:00:00

Link: CVE-2014-8749

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-12-01T15:59:07.877

Modified: 2025-04-12T10:46:40.837

Link: CVE-2014-8749

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.