VYPR

Dtracker

by Dtracker Project

CVEs (4)

  • CVE-2017-1002007HigSep 14, 2017
    risk 0.49cvss 7.5epss 0.05

    Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.

  • CVE-2017-1002006HigSep 14, 2017
    risk 0.49cvss 7.5epss 0.05

    Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.

  • CVE-2017-1002005HigSep 14, 2017
    risk 0.49cvss 7.5epss 0.05

    Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contact_id variable before adding it to the end of an SQL query.

  • CVE-2017-1002004HigSep 14, 2017
    risk 0.49cvss 7.5epss 0.06

    Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query.