Extension WordPress
Vulnérabilités Download Monitor, page 2
Cette page rassemble les failles publiées pour Download Monitor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Download Monitor
29 fiches
Download Monitor <= 4.4.4 – Admin+ SQL Injection via orderby parameter
The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue
[*, 4.4.5)
4.4.5
20/10/2021
Download Monitor <= 1.9.6 – Missing Authorization
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the delete_logs() and export_logs() functions in versions up to, and including, 1.9.6. This makes it possible for unauthenticated attackers to delete…
*-1.9.6
1.9.7
05/05/2017
Download Monitor <= 1.6.4 – Reflected Cross-Site Scripting
The Download Monitor plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping on remove_query_arg and add_query_arg. This makes it possible for attackers to inject…
[*, 1.6.5), 1.7.0
1.6.5, 1.7.1
20/04/2015
Download Monitor < 1.7.1 – Reflected Cross-Site Scripting
The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.
[*, 1.7.1)
1.7.1
20/04/2015
Download Monitor <= 1.6.3 – Directory Listing to Information Disclosure
The Download Monitor plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.6.3 via the 'dir' parameter. This can allow authenticated attackers to extract sensitive data including directories and otherwise restricted server-side…
*-1.6.3
1.6.4
08/03/2015
Download Monitor < 3.3.6.2 – Cross-Site Scripting via sort Parameter
Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the sort parameter, a different vulnerability than CVE-2013-3262.
[*, 3.3.6.2)
3.3.6.2
23/07/2013
Download Monitor < 3.3.6.2 – Cross-Site Scripting via p Parameter
Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the p parameter.
[*, 3.3.6.2)
3.3.6.2
22/07/2013
Download Monitor <= 3.3.5.8 – Reflected Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.
*-3.3.5.8
3.3.5.9
06/09/2012
Download Monitor <= 2.0.6 – Unauthenticated SQL Injection
SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely…
*-2.0.6
2.0.9
28/04/2008
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.