From 09de2eb1946b2acb6b7284577d45aba90475b903 Mon Sep 17 00:00:00 2001 From: Peter Date: Tue, 15 Apr 2014 22:53:24 +0200 Subject: [PATCH] Update vuln db --- data/plugin_vulns.xml | 23 ++++++++++++++++++++--- data/theme_vulns.xml | 21 ++++++++++++++++++++- 2 files changed, 40 insertions(+), 4 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index e20ad2d3..ac26f0bc 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -3120,6 +3120,7 @@ 103308 2014-1889 + 56950 31571 http://packetstormsecurity.com/files/125213/ @@ -3131,6 +3132,7 @@ 103307 2014-1888 + 56950 http://packetstormsecurity.com/files/125212/ XSS @@ -11503,6 +11505,7 @@ all_in_one_carousel 1.2.20 - /tpl/add_carousel.php id Parameter Reflected XSS 103351 + 56962 http://seclists.org/bugtraq/2014/Feb/38 XSS @@ -11738,6 +11741,7 @@ 2014-2340 104402 + 57362 32701 http://packetstormsecurity.com/files/125991/ https://www.htbridge.com/advisory/HTB23206 @@ -12257,12 +12261,25 @@ - Twitget 3.3.1 - CSRF/XSS vulnerability + Twitget 3.3.1 - twitget.php Twitter Setting Manipulation CSRF - https://security.dxw.com/advisories/csrfxss-vulnerability-in-twitget-3-3-1/ + 105705 2014-2559 + 32868 + https://security.dxw.com/advisories/csrfxss-vulnerability-in-twitget-3-3-1/ - MULTI + CSRF + 3.3.3 + + + Twitget 3.3.1 - twitget.php twitget_consumer_key Parameter Stored XSS + + 105704 + 2014-2559 + 32868 + https://security.dxw.com/advisories/csrfxss-vulnerability-in-twitget-3-3-1/ + + XSS 3.3.3 diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index ab73936d..f426a3d0 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -1845,12 +1845,20 @@ - Archin - Cross-Site Scripting and Arbitrary File Upload Vulnerabilities + Archin 3.2 - Cross-Site Scripting and Arbitrary File Upload Vulnerabilities 50711 MULTI + + Archin 3.2 - hades_framework/option_panel/ajax.php Configuration Option Manipulation + + 86991 + 21646 + + RCE + @@ -3508,4 +3516,15 @@ + + + LineNity 1.20 - download.php imgurl Parameter Remote Path Traversal File Access + + 105767 + 32861 + + LFI + + +