cleantalk
Vulnerabilities and Security Researches

Download Monitor, CVE-2012-4768

CVE, Research URL

CVE-2012-4768

Application

Download Monitor

Published on
Sep 04, 2014
Research Description
Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.
Affected versions
Min -, max 3.3.5.9.
Status
vulnerable