CVE Database
/

CVE-2012-4920

Back to search

CVE-2012-4920

Published: Apr 4, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Directory traversal vulnerability in the zing_forum_output function in forum.php in the Zingiri Forum (aka Forums) plugin before 1.4.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter to index.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

50833
third-party-advisory
x_refsource_SECUNIA
89069
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now