Show filters
97 Total Results
Displaying 61-70 of 97
Sort by:
Attacker Value
Unknown

CVE-2017-17968

Disclosure Date: December 29, 2017 (last updated November 26, 2024)
A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long HTTP response.
0
Attacker Value
Unknown

CVE-2017-17849

Disclosure Date: December 27, 2017 (last updated November 26, 2024)
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long response.
0
Attacker Value
Unknown

CVE-2014-9260

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
0
Attacker Value
Unknown

CVE-2017-2216

Disclosure Date: July 07, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2017-2217

Disclosure Date: July 07, 2017 (last updated November 26, 2024)
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
0
Attacker Value
Unknown

CVE-2017-3823

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Download Manager ActiveX control plugin before 2.1.0.10 on Internet Explorer. A vulnerability in these Cisco WebEx browser extensions could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server and Cisco WebEx Centers (Meeting Center, Event Center, Training Center, and Support Center) when they are running on Microsoft Windows. The vulnerability is a design defect in an application programing interface (API) response parser within the extension. An attacker that can convince an affected user to visit an attacker-controlled web page or follow an attacker-supplied link with …
0
Attacker Value
Unknown

CVE-2016-3685

Disclosure Date: December 14, 2016 (last updated November 25, 2024)
SAP Download Manager 2.1.142 and earlier generates an encryption key from a small key space on Windows and Mac systems, which allows context-dependent attackers to obtain sensitive configuration information by leveraging knowledge of a hardcoded key in the program code and a computer BIOS serial number, aka SAP Security Note 2282338.
0
Attacker Value
Unknown

CVE-2016-3684

Disclosure Date: December 14, 2016 (last updated November 25, 2024)
SAP Download Manager 2.1.142 and earlier uses a hardcoded encryption key to protect stored data, which allows context-dependent attackers to obtain sensitive configuration information by leveraging knowledge of this key, aka SAP Security Note 2282338.
0
Attacker Value
Unknown

CVE-2014-8877

Disclosure Date: December 05, 2014 (last updated October 05, 2023)
The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress allows remote attackers to execute arbitrary PHP code via the CMDsearch parameter to cmdownloads/, which is processed by the PHP create_function function.
0
Attacker Value
Unknown

CVE-2014-9129

Disclosure Date: December 05, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the addons_title parameter in the CMDM_admin_settings page to wp-admin/admin.php.
0