RSS   Vulnerabilities for 'Dtracker'   RSS

2017-09-14
 
CVE-2017-1002007

CWE-862
 

 
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.

 
 
CVE-2017-1002006

CWE-862
 

 
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.

 
 
CVE-2017-1002005

CWE-89
 

 
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contact_id variable before adding it to the end of an SQL query.

 
 
CVE-2017-1002004

CWE-89
 

 
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query.

 


Copyright 2024, cxsecurity.com

 

Back to Top