Vulnerabilities > Firestats

DATE CVE VULNERABILITY TITLE RISK
2009-06-22 CVE-2009-2144 SQL Injection vulnerability in multiple products
SQL injection vulnerability in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
edgewall firestats wordpress CWE-89
7.5
2009-06-22 CVE-2009-2143 Code Injection vulnerability in Firestats
PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the fs_javascript parameter.
network
low complexity
wordpress firestats CWE-94
7.5