Lucene search

K

Download-manager Security Vulnerabilities

cve
cve

CVE-2023-22713

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress Download Manager Gutenberg Blocks by WordPress Download Manager plugin <= 2.1.8...

6.5CVSS

5.3AI Score

0.001EPSS

2023-05-03 12:16 PM
14
cve
cve

CVE-2022-2431

The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/Packages.php file that triggers upon download post deletion.....

8.8CVSS

8.8AI Score

0.04EPSS

2022-09-06 06:15 PM
38
5
cve
cve

CVE-2017-20097

A vulnerability was found in WP-Filebase Download Manager Plugin 3.4.4. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched...

6.1CVSS

5.9AI Score

0.001EPSS

2022-06-24 07:15 AM
15
5
cve
cve

CVE-2014-4588

Cross-site scripting (XSS) vulnerability in tpls/editmedia.php in the Hot Files: File Sharing and Download Manager (wphotfiles) plugin 1.0.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the mediaid...

6AI Score

0.001EPSS

2014-07-02 06:55 PM
28
cve
cve

CVE-2009-0183

Stack-based buffer overflow in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allows remote attackers to execute arbitrary code via a long Authorization header in an HTTP...

8AI Score

0.78EPSS

2009-02-03 07:30 PM
38
cve
cve

CVE-2009-0184

Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute arbitrary code via (1) a long file name within a torrent file, (2) a long tracker URL in a torrent file, or (3) a long comment in a...

7.6AI Score

0.672EPSS

2009-02-03 07:30 PM
24
cve
cve

CVE-2005-3769

SQL injection vulnerability in files.php in PHP Download Manager 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the cat...

8.9AI Score

0.002EPSS

2005-11-23 12:03 AM
22