Show filters
97 Total Results
Displaying 51-60 of 97
Sort by:
Attacker Value
Unknown
CVE-2020-24146
Disclosure Date: July 07, 2021 (last updated February 23, 2025)
Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of service via the fileName parameter in a deletescreenshot action.
0
Attacker Value
Unknown
CVE-2020-24145
Disclosure Date: July 07, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted deletescreenshot action.
0
Attacker Value
Unknown
CVE-2020-27344
Disclosure Date: October 21, 2020 (last updated February 22, 2025)
The cm-download-manager plugin before 2.8.0 for WordPress allows XSS.
0
Attacker Value
Unknown
CVE-2020-9688
Disclosure Date: July 17, 2020 (last updated February 21, 2025)
Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2016-6592
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
A vulnerability was found in Symantec Norton Download Manager versions prior to 5.6. A remote user can create a specially crafted DLL file that, when placed on the target user's system, will cause the Norton Download Manager component to load the remote user's DLL instead of the intended DLL and execute arbitrary code when the Norton Download Manager component is run by the target user.
0
Attacker Value
Unknown
CVE-2019-8071
Disclosure Date: October 17, 2019 (last updated November 27, 2024)
Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation.
0
Attacker Value
Unknown
CVE-2019-15889
Disclosure Date: September 03, 2019 (last updated November 27, 2024)
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
0
Attacker Value
Unknown
UDM doesn't check for confinement before running post-processing commands
Disclosure Date: April 22, 2019 (last updated November 27, 2024)
UDM provides support for running commands after a download is completed, this is currently made use of for click package installation. This functionality was not restricted to unconfined applications. Before UDM version 1.2+16.04.20160408-0ubuntu1 any confined application could make use of the UDM C++ API to run arbitrary commands in an unconfined environment as the phablet user.
0
Attacker Value
Unknown
SHDesigns' Resident Download Manager (as well as the Ethernet Download Manager)…
Disclosure Date: July 13, 2018 (last updated November 27, 2024)
SHDesigns' Resident Download Manager provides firmware update capabilities for Rabbit 2000/3000 CPU boards, which according to the reporter may be used in some industrial control and embedded applications. The Resident Download Manager does not verify that the firmware is authentic before executing code and deploying the firmware to devices. A remote attacker with the ability to send UDP traffic to the device may be able to execute arbitrary code on the device. According to SHDesigns' website, the Resident Download Manager and other Rabbit Tools have been discontinued since June 2011.
0
Attacker Value
Unknown
CVE-2017-18032
Disclosure Date: January 16, 2018 (last updated November 26, 2024)
The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-ajax.php.
0