diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index ea5be5ef..43c5689e 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -1804,16 +1804,20 @@ WP Easy Gallery <= 1.7 - Cross Site Scripting + 49190 http://packetstormsecurity.com/files/112687/ XSS + 2.7.3 WP Easy Gallery <= 2.7 - CSRF + 49190 http://plugins.trac.wordpress.org/changeset?reponame=&old=669527%40wp-easy-gallery&new=669527%40wp-easy-gallery CSRF + 2.7.3 @@ -1821,9 +1825,11 @@ Subscribe2 <= 8.0 - Cross Site Scripting + 49189 http://packetstormsecurity.com/files/112688/ XSS + 8.1 @@ -1831,6 +1837,7 @@ Soundcloud Is Gold <= 2.1 - Cross Site Scripting + 49188 http://packetstormsecurity.com/files/112689/ XSS @@ -1913,9 +1920,11 @@ Newsletter Manager <= 1.0 - Cross Site Scripting + 49183 http://packetstormsecurity.com/files/112694/ XSS + 1.0.2 @@ -2042,11 +2051,13 @@ - Code Styling Localization <= 1.99.16 - Cross Site Scripting + Code Styling Localization <= 1.99.17 - Cross Site Scripting + 49037 http://packetstormsecurity.com/files/112709/ XSS + 1.99.20 @@ -2143,9 +2154,11 @@ 2-Click-Socialmedia-Buttons <= 0.32.2 - Cross Site Scripting + 49181 http://packetstormsecurity.com/files/112711/ XSS + 0.35 @@ -3008,9 +3021,11 @@ Mingle Forum <= 1.0.33 - Cross Site Scripting + 49171 http://packetstormsecurity.com/files/112696/ - MULTI + XSS + 1.0.33.2 Mingle Forum 1.0.33.3 - fs-admin.php togroupusers Parameter XSS @@ -7114,6 +7129,7 @@ LBG Zoominoutslider - settings_form.php Multiple Parameter Stored XSS 99339 + http://packetstormsecurity.com/files/123914/ http://seclists.org/fulldisclosure/2013/Nov/30 XSS @@ -7122,6 +7138,7 @@ LBG Zoominoutslider - add_playlist_record.php Multiple Parameter Stored XSS 99340 + http://packetstormsecurity.com/files/123914/ http://seclists.org/fulldisclosure/2013/Nov/30 XSS @@ -7818,10 +7835,11 @@ - Gallery Bank 2.0.19 - Multiple Unspecified XSS + Gallery Bank 2.0.19 - edit-album.php album_id Parameter Reflected XSS 99045 55443 + http://packetstormsecurity.com/files/123924/ http://www.securityfocus.com/bid/63382 XSS @@ -7908,4 +7926,15 @@ + + + Polldaddy Polls and Ratings 2.0.20 - Cross-Site Request Forgery Vulnerability + + 55464 + + CSRF + 2.0.21 + + + diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index 94c6e3d9..62015c25 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -1881,6 +1881,7 @@ Curvo - wp-content/themes/curvo/functions/upload-handler.php File Upload CSRF 99043 + 29211 http://packetstormsecurity.com/files/123799/ http://packetstormsecurity.com/files/123820/ @@ -1924,6 +1925,7 @@ Think Responsive 1.0 - Arbitrary shell upload vulnerability + 29332 http://packetstormsecurity.com/files/123880/ RCE @@ -1952,8 +1954,10 @@ - Switchblade - Arbitrary File Upload Vulnerability + Switchblade 1.3 - Arbitrary File Upload Vulnerability + 88918 + 29330 http://1337day.com/exploit/21457 UPLOAD