dtracker project records
4 published records for vendor dtracker project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-862 Missing Authorization2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2017-1002004No exploit | Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before addindtracker project · dtracker · CWE-89 | High7.5 | — | 3.4% | Sep 14, 2017 |
31Monitor | CVE-2017-1002006No exploit | Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is authorized before injectidtracker project · dtracker · CWE-862 | High7.5 | — | 3.2% | Sep 14, 2017 |
31Monitor | CVE-2017-1002007No exploit | Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting dtracker project · dtracker · CWE-862 | High7.5 | — | 3.2% | Sep 14, 2017 |
31Monitor | CVE-2017-1002005No exploit | Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contact_id variable beforedtracker project · dtracker · CWE-89 | High7.5 | — | 3.2% | Sep 14, 2017 |
- CVE-2017-100200431Monitor
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before addin
HighCVSS 7.5No exploitEPSS 3%dtracker project · dtrackerSep 14, 2017
- CVE-2017-100200631Monitor
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is authorized before injecti
HighCVSS 7.5No exploitEPSS 3%dtracker project · dtrackerSep 14, 2017
- CVE-2017-100200731Monitor
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting
HighCVSS 7.5No exploitEPSS 3%dtracker project · dtrackerSep 14, 2017
- CVE-2017-100200531Monitor
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contact_id variable before
HighCVSS 7.5No exploitEPSS 3%dtracker project · dtrackerSep 14, 2017