vendor:
Plugin: Newsletter
by:
Sammy FORGIT
7,5
CVSS
HIGH
Remote File Disclosure
22
CWE
Product Name: Plugin: Newsletter
Affected Version From: 1.5
Affected Version To: 1.5
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:plugin-newsletter
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
WordPress Plugins – Plugin: Newsletter Remote File Disclosure Vulnerability
A vulnerability in the Plugin: Newsletter plugin for Wordpress allows remote attackers to read arbitrary files via a ../../../../../../../../etc/passwd directory traversal in the data parameter to preview.php.
Mitigation:
Upgrade to the latest version of the Plugin: Newsletter plugin for Wordpress.