|
255881
|
9.8 |
CRITICAL
Network
|
ontraport
|
membership_simplified
|
Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize use…
|
CWE-89
SQL Injection
|
CVE-2017-1002009
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255882
|
9.8 |
CRITICAL
Network
|
membership_simplified_project
|
membership_simplified
|
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a use…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-1002008
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255883
|
7.5 |
HIGH
Network
|
dtracker_project
|
dtracker
|
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.
|
CWE-862
Missing Authorization
|
CVE-2017-1002007
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255884
|
7.5 |
HIGH
Network
|
dtracker_project
|
dtracker
|
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.
|
CWE-862
Missing Authorization
|
CVE-2017-1002006
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255885
|
7.5 |
HIGH
Network
|
dtracker_project
|
dtracker
|
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contact_id variable before adding it to the end of an SQL query.
|
CWE-89
SQL Injection
|
CVE-2017-1002005
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255886
|
7.5 |
HIGH
Network
|
dtracker_project
|
dtracker
|
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query.
|
CWE-89
SQL Injection
|
CVE-2017-1002004
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255887
|
9.8 |
CRITICAL
Network
|
wp2android-turn-wp-site-into-android-app_project
|
wp2android-turn-wp-site-into-android-app
|
Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-1002003
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255888
|
9.8 |
CRITICAL
Network
|
webapp-builder_project
|
webapp-builder
|
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-1002002
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255889
|
9.8 |
CRITICAL
Network
|
mobile-app-builder-by-wappress_project
|
mobile-app-builder-by-wappress
|
Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-1002001
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255890
|
9.8 |
CRITICAL
Network
|
mobile-friendly-app-builder-by-easytouch_project
|
mobile-friendly-app-builder-by-easytouch
|
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-1002000
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|