
CVE-2024-49315 – WordPress FREE DOWNLOAD MANAGER plugin <= 1.0.0 - Arbitrary File Deletion vulnerability
https://notcve.org/view.php?id=CVE-2024-49315
15 Oct 2024 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CodeFlock FREE DOWNLOAD MANAGER allows Path Traversal.This issue affects FREE DOWNLOAD MANAGER: from n/a through 1.0.0. The FREE DOWNLOAD MANAGER plugin for WordPress is vulnerable to Arbitrary File Downloads in all versions up to, and including, 1.0.0 via the download_stats_updated() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can co... • https://patchstack.com/database/vulnerability/free-download-manager/wordpress-free-download-manager-plugin-1-0-0-arbitrary-file-deletion-vulnerability?_s_id=cve • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2010-0998
https://notcve.org/view.php?id=CVE-2010-0998
17 May 2010 — Multiple stack-based buffer overflows in Free Download Manager (FDM) before 3.0.852 allow remote attackers to execute arbitrary code via vectors involving (1) the folders feature in Site Explorer, (2) the websites feature in Site Explorer, (3) an FTP URI, or (4) a redirect. Múltiple desbordamiento de búfer basado en pila en Free Download Manager (FDM) anteriores a v3.0.852, permite a atacantes remotos ejecutar código de su elección a través de vectores que implican las características (1) "folders" en Site ... • http://osvdb.org/64671 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2010-0999
https://notcve.org/view.php?id=CVE-2010-0999
17 May 2010 — Directory traversal vulnerability in Free Download Manager (FDM) before 3.0.852 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file. Vulnerabilidad de salto de directorio en Free Download Manager (FDM) anteriores a v3.0.852, permite a atacantes remotos crear ficheros de su elección al utilizar caracteres .. (punto punto) en el atributo nombre de un elemento fichero en un fichero metalink. • http://osvdb.org/64670 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •