cleantalk
Vulnerabilities and Security Researches

Download Monitor, CVE-2013-5098

CVE, Research URL

CVE-2013-5098

Application

Download Monitor

Published on
Aug 10, 2013
Research Description
Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the sort parameter, a different vulnerability than CVE-2013-3262.
Affected versions
Min -, max 3.3.6.2.
Status
vulnerable