diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index b0197cc6..b905cc9d 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -2926,6 +2926,14 @@ + + Zingiri Web Shop 2.6.5 - fwkfor/ajax/uploadfilexd.php Unspecified Issue + + 103554 + + UNKNOWN + 2.6.6 + Zingiri Web Shop 2.6.4 - mform.php Unspecified Issue @@ -6247,6 +6255,43 @@ + + Welcart e-Commerce 1.3.12 - wp-admin/admin-ajax.php Multiple Parameter DOM-Based XSS + + 103956 + 57222 + http://packetstormsecurity.com/files/125513/ + http://www.securityfocus.com/bid/65954 + + XSS + + + Welcart e-Commerce 1.3.12 - purchase_limit Parameter DOM-based XSS + + 103955 + http://packetstormsecurity.com/files/125513/ + http://www.securityfocus.com/bid/65954 + + XSS + + + Welcart e-Commerce 1.3.12 - wp-admin/admin.php Multiple Parameter SQL Injection + + 103954 + http://packetstormsecurity.com/files/125513/ + http://www.securityfocus.com/bid/65954 + + SQLI + + + Welcart e-Commerce - wp-admin/admin.php Multiple Parameter SQL Injection + + 103954 + http://packetstormsecurity.com/files/125513/ + http://www.securityfocus.com/bid/65954 + + SQLI + Welcart e-Commerce - Cross-Site Scripting and Request Forgery Vulnerabilities @@ -11303,9 +11348,13 @@ - CSRF in WordPress plugin Google Analytics MU 2.3 + Google Analytics MU 2.3 - google-analytics-mu-network.php Analytics Code Manipulation CSRF + 103937 + 56157 + http://packetstormsecurity.com/files/125514/ http://seclists.org/fulldisclosure/2014/Mar/20 + http://www.securityfocus.com/bid/65926 CSRF 2.4