From cfc53f67f989a000a1172378c0e134a8fbbf2b3a Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Tue, 5 Nov 2013 20:19:41 +0100 Subject: [PATCH 1/5] Update plugin_vulns.xml --- data/plugin_vulns.xml | 37 ++++++++++++++++++++++++++----------- 1 file changed, 26 insertions(+), 11 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index d06857ee..292570c3 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -4612,13 +4612,11 @@ - WP-Super-Cache - Remote Code Execution + WP-Super-Cache 1.3 - Remote Code Execution http://www.acunetix.com/blog/web-security-zone/wp-plugins-remote-code-execution/ http://wordpress.org/support/topic/pwn3d - - http://blog.sucuri.net/2013/04/update-wp-super-cache-and-w3tc-immediately-remote-code-execution-vulnerability-disclosed.html - + http://blog.sucuri.net/2013/04/update-wp-super-cache-and-w3tc-immediately-remote-code-execution-vulnerability-disclosed.html RCE 1.3.1 @@ -6308,8 +6306,10 @@ - Related Posts by Zemanta - Cross-Site Request Forgery Vulnerability + Related Posts by Zemanta 1.3.1 - Cross-Site Request Forgery Vulnerability + 93364 + 2013-3477 53321 CSRF @@ -6319,19 +6319,22 @@ - WordPress Related Posts - Cross-Site Request Forgery Vulnerability + WordPress Related Posts 2.6.1 - Cross-Site Request Forgery Vulnerability + 93362 + 2013-3476 53279 CSRF - 2.6.2 + 2.7.2 - Related Posts - Cross-Site Request Forgery Vulnerability + Related Posts 2.7.1 - Cross-Site Request Forgery Vulnerability + 93363 53122 CSRF @@ -6444,12 +6447,14 @@ - FunCaptcha - CSRF + FunCaptcha 0.3.2- Setting Manipulation CSRF + 92272 + 53021 http://wordpress.org/extend/plugins/funcaptcha/changelog/ - UNKNOWN - 0.33 + CSRF + 0.3.3 @@ -7892,4 +7897,14 @@ + + + Live Comment Preview 2.0.2 - Comment Field Preview XSS + + 92944 + + XSS + + + From a825774341e8a730057a1b4f3002f6ae66548643 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Wed, 6 Nov 2013 08:56:35 +0100 Subject: [PATCH 2/5] Added OSVDB #99345 --- data/plugin_vulns.xml | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 292570c3..4cbd9f16 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -7847,6 +7847,17 @@ UNKNOWN 2.0.20 + + Gallery Bank 2.0.19 - album-gallery-bank-class.php recordsArray Parameter Reflected XSS + + 99345 + 55443 + http://www.securityfocus.com/bid/63385 + http://seclists.org/fulldisclosure/2013/Nov/38 + + XSS + 2.0.20 + From 7122ca872ab3df82219be91ab9058a13ecec313b Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Wed, 6 Nov 2013 09:09:22 +0100 Subject: [PATCH 3/5] Added Exploit-DB #29150 --- data/theme_vulns.xml | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index 3b6e583d..27591241 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -1881,6 +1881,7 @@ 99043 http://packetstormsecurity.com/files/123799/ + http://packetstormsecurity.com/files/123820/ CSRF @@ -1897,6 +1898,16 @@ + + + Saico - Arbitrary File Upload Vulnerability + + 29150 + + UPLOAD + + + ThisWay - remote shell upload vulnerability From c751009130c058dfc8376cea86f66500a5978c40 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Wed, 6 Nov 2013 09:28:17 +0100 Subject: [PATCH 4/5] Update plugin_vulns.xml --- data/plugin_vulns.xml | 1 + 1 file changed, 1 insertion(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 4cbd9f16..9293a3c9 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -7592,6 +7592,7 @@ 98668 55296 28970 + http://packetstormsecurity.com/files/123597/ http://www.securityfocus.com/bid/63021 XSS From b14ded29947a6437926ed75366228405b8a4e33c Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Wed, 6 Nov 2013 09:39:05 +0100 Subject: [PATCH 5/5] Update wp_vulns.xml --- data/wp_vulns.xml | 1 + 1 file changed, 1 insertion(+) diff --git a/data/wp_vulns.xml b/data/wp_vulns.xml index 45ea1596..e98941fc 100644 --- a/data/wp_vulns.xml +++ b/data/wp_vulns.xml @@ -34,6 +34,7 @@ 97212 2013-4339 54803 + http://packetstormsecurity.com/files/123589/ http://core.trac.wordpress.org/changeset/25323 UNKNOWN