CVE-2012-3588
medium · 5Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the data parameter.
5
CVSS
10.7%
EPSS (exploit prob.)
96th
EPSS percentile
2012-06-19
Published
AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| wordpress | plugin_newsletter_plugin | 1.5 |
| wordpress | wordpress | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://secunia.com/advisories/49464
- http://www.exploit-db.com/exploits/19018
- http://www.opensyscom.fr/Actualites/wordpress-plugins-plugin-newsletter-remote-file-disclosure-vulnerability.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76171
- http://secunia.com/advisories/49464
- http://www.exploit-db.com/exploits/19018
- http://www.opensyscom.fr/Actualites/wordpress-plugins-plugin-newsletter-remote-file-disclosure-vulnerability.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76171
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-3588