PT-2008-3199 · WordPress · Wp-Download
Bl4Ck
·
Published
2008-04-02
·
Updated
2017-09-29
·
CVE-2008-1646
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
WP-Download plugin for WordPress version 1.2
Description
A SQL injection issue allows remote attackers to execute arbitrary SQL commands. The issue is exploited via the
dl id parameter in the wp-download.php file.Recommendations
For WP-Download plugin for WordPress version 1.2, consider restricting access to the wp-download.php file until a patch is available, and avoid using the
dl id parameter in the affected endpoint.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp-Download