RULE(RULE ID:338428)

Rule General Information
Release Date: 2024-09-18
Rule Name: WordPress plugin WP AmASIN - The Amazon Affiliate Shop Arbitrary File Reading Vulnerability (CVE-2014-4577)
Severity:
CVE ID:
Rule Protection Details
Description: Absolute path traversal vulnerability in reviews.php in the WP AmASIN - The Amazon Affiliate Shop plugin 0.9.6 and earlier for WordPress allows remote attackers to read arbitrary files via a full pathname in the url parameter.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: http://codevigilant.com/disclosure/wp-plugin-wp-amasin-the-amazon-affiliate-shop-local-file-inclusion
http://plugins.svn.wordpress.org/wp-amasin-the-amazon-affiliate-shop/trunk/readme.txt
Solutions
Refer to the announcement or patch by the vendor: http://plugins.svn.wordpress.org/wp-amasin-the-amazon-affiliate-shop/trunk/readme.txt