Absolute path traversal vulnerability in reviews.php in the WP AmASIN - The Amazon Affiliate Shop plugin 0.9.6 and earlier for WordPress allows remote attackers to read arbitrary files via a full pathname in the url parameter.
id: CVE-2014-4577
info:
name: WP AmASIN – The Amazon Affiliate Shop - Local File Inclusion
auth
...