diff --git a/data/wp_vulns.xml b/data/wp_vulns.xml index f2f2b9a4..e9a15173 100644 --- a/data/wp_vulns.xml +++ b/data/wp_vulns.xml @@ -32,20 +32,20 @@ This file contains vulnerabilities associated with WordPress verions. - - Wordpress 3.3.1 Multiple CSRF Vulnerabilities - http://www.exploit-db.com/exploits/18791/ + + Wordpress 3.3.1 Multiple CSRF Vulnerabilities + http://www.exploit-db.com/exploits/18791/ - - Wordpress 3.3.1 Multiple CSRF Vulnerabilities - http://www.exploit-db.com/exploits/18791/ + + Wordpress 3.3.1 Multiple CSRF Vulnerabilities + http://www.exploit-db.com/exploits/18791/ - - WordPress 3.3.2 Cross Site Scripting - http://packetstormsecurity.org/files/113254 + + WordPress 3.3.2 Cross Site Scripting + http://packetstormsecurity.org/files/113254 @@ -54,9 +54,13 @@ This file contains vulnerabilities associated with WordPress verions. Multiple vulnerabilities including XSS and Privilege Escalation http://wordpress.org/news/2012/04/wordpress-3-3-2/ - - Wordpress 3.3.1 Multiple CSRF Vulnerabilities - http://www.exploit-db.com/exploits/18791/ + + Wordpress 3.3.1 Multiple CSRF Vulnerabilities + http://www.exploit-db.com/exploits/18791/ + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 @@ -65,6 +69,31 @@ This file contains vulnerabilities associated with WordPress verions. Reflected Cross-Site Scripting in WordPress 3.3 http://oldmanlab.blogspot.com/2012/01/wordpress-33-xss-vulnerability.html + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + @@ -72,6 +101,10 @@ This file contains vulnerabilities associated with WordPress verions. Multiple SQL Injection Vulnerabilities http://www.exploit-db.com/exploits/17465/ + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + @@ -79,6 +112,10 @@ This file contains vulnerabilities associated with WordPress verions. Wordpress <= 3.1.2 Clickjacking Vulnerability http://seclists.org/fulldisclosure/2011/Sep/219 + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + @@ -86,6 +123,38 @@ This file contains vulnerabilities associated with WordPress verions. WordPress wp-includes/formatting.php make_clickable() PCRE Library Remote DoS http://osvdb.org/show/osvdb/72142 + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + @@ -97,6 +166,10 @@ This file contains vulnerabilities associated with WordPress verions. Wordpress 3.0.3 stored XSS IE7,6 NS8.1 http://www.exploit-db.com/exploits/15858/ + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + @@ -104,6 +177,10 @@ This file contains vulnerabilities associated with WordPress verions. WordPress XML-RPC Interface Access Restriction Bypass http://osvdb.org/69761 + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + @@ -111,6 +188,31 @@ This file contains vulnerabilities associated with WordPress verions. WordPress: Information Disclosure via SQL Injection Attack http://blog.sjinks.pro/wordpress/858-information-disclosure-via-sql-injection-attack/ + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + @@ -122,6 +224,17 @@ This file contains vulnerabilities associated with WordPress verions. Wordpress DOS <= 2.9 http://www.exploit-db.com/exploits/11441/ + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + @@ -129,6 +242,17 @@ This file contains vulnerabilities associated with WordPress verions. WordPress <= 2.8.5 Unrestricted File Upload Arbitrary PHP Code Execution http://www.exploit-db.com/exploits/10089/ + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + @@ -136,6 +260,10 @@ This file contains vulnerabilities associated with WordPress verions. Wordpress <= 2.8.3 Remote Admin Reset Password Vulnerability http://www.exploit-db.com/exploits/9410/ + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + @@ -143,6 +271,17 @@ This file contains vulnerabilities associated with WordPress verions. Wordpress 2.8.1 (url) Remote Cross Site Scripting Exploit http://www.exploit-db.com/exploits/9250/ + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + @@ -150,6 +289,45 @@ This file contains vulnerabilities associated with WordPress verions. WordPress 2.0 - 2.7.1 admin.php Module Configuration Security Bypass Vulnerability http://www.exploit-db.com/exploits/10088/ + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + @@ -157,6 +335,31 @@ This file contains vulnerabilities associated with WordPress verions. Wordpress 2.6.1 (SQL Column Truncation) Admin Takeover Exploit http://www.exploit-db.com/exploits/6421/ + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + + + + + + XSS vulnerability in swfupload in WordPress + http://seclists.org/fulldisclosure/2012/Nov/51 + @@ -237,4 +440,4 @@ This file contains vulnerabilities associated with WordPress verions. - + \ No newline at end of file