VYPR

dl_stats

by Dl Stats

CVEs (2)

  • CVE-2022-44051CriNov 7, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-math package. The affected version of d8s-htm is 0.1.0.

  • CVE-2010-1497Apr 23, 2010
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in download_proc.php in dl_stats before 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.