Information Disclosure in VideoWhisper Live Streaming Integration for WordPress
CVE-2014-1908
Currently unrated
What is CVE-2014-1908?
The VideoWhisper Live Streaming Integration plugin for WordPress has a flaw in its error-handling mechanism. This vulnerability allows remote attackers to exploit specific scripts, including bp.php, videowhisper_streaming.php, and ls/rtmp.inc.php. By sending direct requests, attackers can trigger error messages revealing sensitive information such as the full file path, which can potentially assist in further attacks against the affected system.