Firestats [firestats] < 1.6.6
unknown
This Firestats plugin is prone to remote file-include vulnerability. It fails to clean user data sufficiently. The attacker may compromise the application and the other attacks are possible.
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.6
- Disclosed:
- Jul 9, 2010
Firestats [firestats] <= 1.0.2
unknown
FireStats plugin is prone to multiple cross-site scripting vulnerabilities and an authentication BYPASS vulnerabilities. An attacker may gain unauthorized access to the affected application and execute arbitrary script code in the context of the affected site. In that way the attacker can steal cookie-based authentica...
- Affected:
- up to 1.0.2
- Fixed in:
- 1.0.2
- Disclosed:
- Nov 24, 2009
FireStats <1.6.2 - SQL Injection
critical
SQL injection vulnerability in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
- CVSS:
- 10
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.2
- Disclosed:
- Jun 22, 2009
CVE-2009-2144 on NVD →
Firestats [firestats] < 1.6.2 (closed)
unknown
[en] PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the fs_javascript parameter.
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.2
- Disclosed:
- Jun 22, 2009
CVE-2009-2143 on NVD →
Firestats [firestats] < 1.6.2 (closed)
unknown
[en] SQL injection vulnerability in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.2
- Disclosed:
- Jun 22, 2009
CVE-2009-2144 on NVD →
FireStats < 1.6.2 - Remote File Inclusion
critical
PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the fs_javascript parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.2
- Disclosed:
- Jun 12, 2009
CVE-2009-2143 on NVD →
Firestats [firestats] < 100 (unfixed + closed)
unknown
The firestats WordPress plugin was affected by a Remote Configuration File Download security vulnerability.
- Affected:
- up to 100
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database