CVE-2012-4920

EUVD-2012-4845
Directory traversal vulnerability in the zing_forum_output function in forum.php in the Zingiri Forum (aka Forums) plugin before 1.4.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter to index.php.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
Affected Products (NVD)
VendorProductVersion
zingiriforums
𝑥
≤ 1.4.3
zingiriforums
1.0.0
zingiriforums
1.0.1
zingiriforums
1.0.2
zingiriforums
1.0.3
zingiriforums
1.0.4
zingiriforums
1.0.5
zingiriforums
1.0.6
zingiriforums
1.0.7
zingiriforums
1.0.8
zingiriforums
1.0.9
zingiriforums
1.1.0
zingiriforums
1.1.1
zingiriforums
1.2.0
zingiriforums
1.2.1
zingiriforums
1.3.0
zingiriforums
1.3.1
zingiriforums
1.4.0
zingiriforums
1.4.1
zingiriforums
1.4.2
𝑥
= Vulnerable software versions