CVE-2014-8754 Information

Description

Open redirect vulnerability in track-click.php in the Ad-Manager plugin 1.1.2 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the out parameter.

Reference

http://packetstormsecurity.com/files/129290/WordPress-Ad-Manager-1.1.2-Open-Redirect.html http://seclists.org/fulldisclosure/2014/Nov/93 http://tetraph.com/security/cves/cve-2014-8754-wordpress-ad-manager-plugin-dest-redirect-privilege-escalation/ https://exchange.xforce.ibmcloud.com/vulnerabilities/98990

Share on: