cpe:/a:arnos_toolbox:wp-download:1.2 cpe:/a:wordpress:wp_download:1.2 CVE-2008-1646 2008-04-02T13:44:00.000-04:00 2017-09-28T21:30:48.240-04:00 7.5 NETWORK LOW NONE PARTIAL PARTIAL PARTIAL http://nvd.nist.gov 2008-04-03T13:43:00.000-04:00 ALLOWS_OTHER_ACCESS BID 28516 SECUNIA 29608 EXPLOIT-DB 5326 XF wpdownload-wpdownload-sql-injection(41552) SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the dl_id parameter.