WP AmASIN – The Amazon Affiliate Shop <= 0.9.6 - Local File Inclusion
highAbsolute path traversal vulnerability in reviews.php in the WP AmASIN - The Amazon Affiliate Shop plugin 0.9.6 and earlier for WordPress allows remote attackers to read arbitrary files via a full pathname in the url parameter.
- CVSS:
- 7.5
- Affected:
- up to 0.9.6
- Fixed in:
- 0.9.7
- Disclosed:
- Aug 1, 2014