Ripe HD FLV <= 1.1 - SQL Injection
critical
The Ripe HD FLV plugin for WordPress is vulnerable to generic SQL Injection via the 'id' parameter in the 'config.php' file in versions up to, and including, 1.1 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthen...
- CVSS:
- 9.8
- Affected:
- up to 1.1
- Fix:
- No patched version reported
- Disclosed:
- Jan 20, 2013
Ripe HD FLV <= 1.1 - Full Path Disclosure
medium
The Ripe HD FLV plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.1 via the 'index.php' and 'installer.php' files. This can allow unauthenticated attackers to extract sensitive data including the full path of the installation.
- CVSS:
- 5.3
- Affected:
- up to 1.1
- Fix:
- No patched version reported
- Disclosed:
- Jan 20, 2013
Hitasoft FLV Player [ripe-hd-player] <= 1.1 (unfixed + closed)
unknown
The Ripe HD FLV plugin for WordPress is vulnerable to generic SQL Injection via the 'id' parameter in the 'config.php' file in versions up to, and including, 1.1 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthen...
- Affected:
- up to 1.1
- Fix:
- No patched version reported
- Disclosed:
- Jan 20, 2013
Hitasoft FLV Player [ripe-hd-player] <= 1.1 (unfixed + closed)
unknown
The Ripe HD FLV plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.1 via the 'index.php' and 'installer.php' files. This can allow unauthenticated attackers to extract sensitive data including the full path of the installation.
- Affected:
- up to 1.1
- Fix:
- No patched version reported
- Disclosed:
- Jan 20, 2013
Hitasoft FLV Player [ripe-hd-player] < 1.1 (closed)
unknown
WordPress Ripe HD FLV Player plugin is prone to an SQL injection vulnerability. It allows an attacker to get access to the database, get username, password and disclosure the full path.
Update the plugin.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Jan 19, 2013
Hitasoft FLV Player [ripe-hd-player] <= 1.0 (unfixed + closed)
unknown
The ripe-hd-player WordPress plugin was affected by a Multiple Script Direct Request Path Disclosure security vulnerability.
- Affected:
- up to 1.0
- Fix:
- No patched version reported
Hitasoft FLV Player [ripe-hd-player] <= 1.0 (unfixed + closed)
unknown
The ripe-hd-player WordPress plugin was affected by a ripe-hd-player/config.php id Parameter SQL Injection security vulnerability.
- Affected:
- up to 1.0
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database