CVE

CVE-2008-1646 — Download Monitor [download-monitor] < 1.2.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2008-1646 Download Monitor [download-monitor] < 1.2.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Unknown < 1.2.1 1.2.1 2008-03-31

CVE-2008-1646

The WP-Download plugin for WordPress versions before 1.2.1 contains a SQL injection vulnerability in the wp-download.php file that allows attackers to execute arbitrary SQL queries by manipulating the dl_id parameter.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.