Extension WordPress
Vulnérabilités Count per Day
Cette page rassemble les failles publiées pour Count per Day, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Count per Day
10 fiches
Count per Day < 3.5.5 – Unauthenticated Stored Cross-Site Scripting
The Count per Day plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
[*, 3.5.5)
3.5.5
05/08/2016
Count per Day < 3.5.5 – Reflected Cross-Site Scripting
The Count per Day plugin for WordPress is vulnerable to Cross-Site Scripting via the 'limit' parameter in versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers…
[*, 3.5.5)
3.5.5
04/08/2016
Count per Day <= 3.4 – Cross-Site Request Forgery
SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php. NOTE: this can be leveraged using CSRF to…
[*, 3.4.1)
3.4.1
22/07/2015
Count Per Day <= 3.1.1 – Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in userperspan.php in the Count Per Day module before 3.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) datemin, or (3) datemax parameter.
*-3.1.1
3.2
01/08/2014
Count Per Day <= 3.2.3 – Path Disclosure and Denial of Service
The Count Per Day plugin for WordPress is vulnerable to Path Disclosure and Denial of Service in versions up to, and including, 3.2.3 via the 'notes.php' file. This makes it possible for unauthenticated attackers to disclose sensitive information…
*-3.2.3
3.2.4
01/08/2014
Count per Day < 3.2.6 – Reflected Cross-Site Scripting
The Count per Day plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP Referer header in versions before 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
[*, 3.2.6)
3.2.6
01/08/2014
Count per Day <= 3.1 – Cross-Site Scripting
The Count per Day plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘map’ parameter in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-3.1
3.1.1
01/08/2014
Count per Day < 3.2.6 – Cross-Site Scripting
The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow parameter.
[*, 3.2.6)
3.2.6
05/03/2013
Count per Day Plugin < 3.2.3 – Cross-Site Scripting
The count-per-day plugin before 3.2.3 for WordPress has XSS via search words.
[*, 3.2.3)
3.2.3
20/07/2012
Count per Day <= 3.1 – Arbitrary File Download
Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.
*-3.1
3.1.1
12/01/2012
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.