Vulnerabilities
Vulnerable Software
Zingiri:  Security Vulnerabilities
Directory traversal vulnerability in the zing_forum_output function in forum.php in the Zingiri Forum (aka Forums) plugin before 1.4.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter to index.php.
CVSS Score
5.0
EPSS Score
0.013
Published
2014-04-04
Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in zing.inc.php or (2) notes parameter in fws/pages-front/onecheckout.php.
CVSS Score
4.3
EPSS Score
0.047
Published
2013-01-24
Multiple unspecified vulnerabilities in the Zingiri Web Shop plugin before 2.4.0 for WordPress have unknown impact and attack vectors.
CVSS Score
10.0
EPSS Score
0.014
Published
2012-07-18
PHP remote file inclusion vulnerability in ajax/savetag.php in the Theme Tuner plugin for WordPress before 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the tt-abspath parameter.
CVSS Score
7.5
EPSS Score
0.015
Published
2012-01-29


Contact Us

Shodan ® - All rights reserved