fl4p / WP-Filebase

WP-Filebase
http://wpfilebase.com/
34 stars 35 forks source link

Possible security flaw #41

Open yatishmadhav opened 8 years ago

yatishmadhav commented 8 years ago

Hi Fabian

Please see log from a WPscan on the plugin ...

WP-Filebase Download Manager <= 0.2.9 - wpfb-ajax.php base Parameter SQL Injection Reference: [https://wpvulndb.com/vulnerabilities/6553] Reference: [https://secunia.com/advisories/45931/] Reference: [https://www.exploit-db.com/exploits/17808/]

Please advise when the update to that will be made?

Thanks

fl4p commented 8 years ago

Get the latest version here: https://github.com/f4bsch/WP-Filebase/archive/master.zip

yatishmadhav commented 8 years ago

Thanks mate - so https://wordpress.org/plugins/wp-filebase/ has 3.4.4 - how frequently is that updated with this 3.4.5? I usually wait for the updates to show up in the WP console ... Appreciate it @f4bsch

I still feel so new to Wordpress even after over 2 years working on it! :D

yatishmadhav commented 8 years ago

Hi there, Any idea on the above please? Thanks man

yatishmadhav commented 8 years ago

Hey there - it is missing again from the WP repo? I am trying to understand if it dissappears off there because of updates? Or some other reason? Thanks in advance, Fabian

yatishmadhav commented 7 years ago

Hey Fabian,,,,, Hope you are well? Please advise on the last comment? Thanks. Cheers