Vulnerability Description
Absolute path traversal vulnerability in reviews.php in the WP AmASIN - The Amazon Affiliate Shop plugin 0.9.6 and earlier for WordPress allows remote attackers to read arbitrary files via a full pathname in the url parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Websupporter | Wp Amasin - The Amazon Affiliate Shop | <= 0.9.6 |
Related Weaknesses (CWE)
References
- http://codevigilant.com/disclosure/wp-plugin-wp-amasin-the-amazon-affiliate-shopExploit
- http://plugins.svn.wordpress.org/wp-amasin-the-amazon-affiliate-shop/trunk/readmVendor Advisory
- http://codevigilant.com/disclosure/wp-plugin-wp-amasin-the-amazon-affiliate-shopExploit
- http://plugins.svn.wordpress.org/wp-amasin-the-amazon-affiliate-shop/trunk/readmVendor Advisory
FAQ
What is CVE-2014-4577?
CVE-2014-4577 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Absolute path traversal vulnerability in reviews.php in the WP AmASIN - The Amazon Affiliate Shop plugin 0.9.6 and earlier for WordPress allows remote attackers to read arbitrary files via a full path...
How severe is CVE-2014-4577?
CVE-2014-4577 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-4577?
Check the references section above for vendor advisories and patch information. Affected products include: Websupporter Wp Amasin - The Amazon Affiliate Shop.