Show filters
97 Total Results
Displaying 71-80 of 97
Sort by:
Attacker Value
Unknown

CVE-2014-8585

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views/file_download.php or (2) file_download.php.
0
Attacker Value
Unknown

CVE-2014-4588

Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in tpls/editmedia.php in the Hot Files: File Sharing and Download Manager (wphotfiles) plugin 1.0.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the mediaid parameter.
0
Attacker Value
Unknown

CVE-2014-2087

Disclosure Date: March 18, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8 build 1173, 3.0 build 852, and earlier allows user-assisted remote attackers to execute arbitrary code via a long file name, which is then deleted from the download queue by the user.
0
Attacker Value
Unknown

CVE-2014-2206

Disclosure Date: March 05, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long HTTP Response Header.
0
Attacker Value
Unknown

CVE-2013-7319

Disclosure Date: February 06, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.
0
Attacker Value
Unknown

CVE-2012-0980

Disclosure Date: February 02, 2012 (last updated October 04, 2023)
SQL injection vulnerability in download.php in phux Download Manager allows remote attackers to execute arbitrary SQL commands via the file parameter.
0
Attacker Value
Unknown

CVE-2010-0998

Disclosure Date: May 17, 2010 (last updated October 04, 2023)
Multiple stack-based buffer overflows in Free Download Manager (FDM) before 3.0.852 allow remote attackers to execute arbitrary code via vectors involving (1) the folders feature in Site Explorer, (2) the websites feature in Site Explorer, (3) an FTP URI, or (4) a redirect.
0
Attacker Value
Unknown

CVE-2010-0999

Disclosure Date: May 17, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in Free Download Manager (FDM) before 3.0.852 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.
0
Attacker Value
Unknown

CVE-2010-0995

Disclosure Date: May 06, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in Internet Download Manager (IDM) before 5.19 allows remote attackers to execute arbitrary code via a crafted FTP URI that causes unspecified "test sequences" to be sent from client to server.
0
Attacker Value
Unknown

CVE-2010-0189

Disclosure Date: February 23, 2010 (last updated October 04, 2023)
A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving web sites that are not in subdomains, which allows remote attackers to force the download and installation of arbitrary programs via a crafted name for a download site.
0