From 0c406d72f6ec8d18c7df5620de2da1c9a33d361f Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Fri, 25 Oct 2013 11:48:22 +0200 Subject: [PATCH] Update WordPress Theme vulns --- data/theme_vulns.xml | 46 +++++++++++++++++++++++++++++++++++++++----- 1 file changed, 41 insertions(+), 5 deletions(-) diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index 37b89e22..0ae6c0ce 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -1248,9 +1248,11 @@ - DailyDeal - Shell Upload + DailyDeal - File Upload Remote Code Execution + 98924 http://packetstormsecurity.com/files/123748/ + http://templatic.com/app-themes/daily-deal-premium-wordpress-app-theme RCE @@ -1730,7 +1732,7 @@ - silverOrchid - XSS Vulnerability + silverOrchid <= 1.5.0 - XSS Vulnerability 96723 54662 @@ -1744,9 +1746,9 @@ Caulk - path disclosure vulnerability - 96723 - 54662 + 90889 http://packetstormsecurity.com/files/120632/ + http://themeforest.net/item/caulk/76108 FPD @@ -1759,7 +1761,7 @@ 98806 http://packetstormsecurity.com/files/123697/ - UNKNOWN + RCE @@ -1818,4 +1820,38 @@ + + + AREA53 <= 1.0.5 - File Upload Code Execution + + 98927 + 29068 + http://www.securityfocus.com/bid/63306 + http://themeforest.net/item/area53-a-responsive-html5-wordpress-theme/2538737 + + RCE + + + + + + Sahifa 2.4.0 - Multiple Script Path Disclosure Direct Request Path Disclosure + + 88926 + http://packetstormsecurity.com/files/119191/ + http://www.securityfocus.com/bid/57109 + + FPD + + + Sahifa 2.4.0 - Site Setting Reset CSRF + + 88927 + http://packetstormsecurity.com/files/119191/ + http://www.securityfocus.com/bid/57109 + + CSRF + + +