From 102585e4c752dc3e0a2e856e4bd10ed2d509d252 Mon Sep 17 00:00:00 2001 From: erwanlr Date: Sun, 16 Jun 2013 12:20:45 +0200 Subject: [PATCH] Added some vulns, references, CVEs (Ref #184) --- data/plugin_vulns.xml | 159 +++++++++++++++++++++++++++++++++++++----- data/wp_vulns.xml | 2 + 2 files changed, 143 insertions(+), 18 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 2195aac4..8a688ee5 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -3,6 +3,50 @@ + + + Content Slide Plugin Cross-Site Requst Forgery Vulnerability + http://secunia.com/advisories/52949/ + http://osvdb.org/show/osvdb/93871 + CSRF + + + + + + Simple Paypal Shopping Cart Plugin Cross-Site Request Forgery Vulnerability + http://secunia.com/advisories/52963/ + http://osvdb.org/show/osvdb/93953 + CSRF + 3.6 + + + + + + WP-SendSMS Plugin for WordPress Setting Manipulation CSRF + http://secunia.com/advisories/53796/ + http://osvdb.org/show/osvdb/94209 + http://www.exploit-db.com/exploits/26124 + CSRF + + + WP-SendSMS Plugin for WordPress wp-admin/admin.php Multiple Parameter XSS + http://osvdb.org/show/osvdb/94210 + XSS + + + + + + Mail Subscribe List Plugin Script Insertion Vulnerability + http://secunia.com/advisories/53732/ + http://osvdb.org/show/osvdb/94197 + XSS + 2.1 + + + VideoJS Cross-Site Scripting Vulnerability @@ -12,7 +56,7 @@ 0.98 - + VideoJS Cross-Site Scripting Vulnerability @@ -22,7 +66,7 @@ 4.1 - + VideoJS Cross-Site Scripting Vulnerability @@ -32,7 +76,7 @@ 1.4 - + VideoJS Cross-Site Scripting Vulnerability @@ -42,7 +86,7 @@ 2.1 - + VideoJS Cross-Site Scripting Vulnerability @@ -50,7 +94,7 @@ XSS - + Crayon Syntax Highlighter Remote File Inclusion @@ -2006,6 +2050,13 @@ SQLI 2.56 + + GRAND FlAGallery Plugin "s" Cross-Site Scripting Vulnerability + http://secunia.com/advisories/53111/ + http://osvdb.org/show/osvdb/93714 + XSS + 2.72 + @@ -3424,6 +3475,8 @@ WordPress Events Manager Multiple Cross Site Scripting Vulnerabilities http://www.securityfocus.com/bid/60078 + http://secunia.com/advisories/53478/ + http://osvdb.org/show/osvdb/93558 XSS 5.3.9 @@ -4529,7 +4582,7 @@ XSS - WordPress plugin uk-cookie CSRF + CVE-2013-2180: uk-cookie CSRF http://www.openwall.com/lists/oss-security/2013/06/06/10 CSRF @@ -4537,10 +4590,14 @@ - CVE-2013-2108|CVE-2013-2109: wp-cleanfix Remote Command Execution and CSRF + CVE-2013-2108|CVE-2013-2109: wp-cleanfix Remote Command Execution, CSRF and XSS https://github.com/wpscanteam/wpscan/issues/186 http://wordpress.org/support/topic/plugin-wp-cleanfix-remote-code-execution-warning - RCE + http://osvdb.org/show/osvdb/93450 + http://secunia.com/advisories/53395/ + http://osvdb.org/show/osvdb/93468 + MULTI + 3.0.2 @@ -4552,7 +4609,7 @@ CSRF - + Advanced XML Reader Plugin for WordPress XML External Entity (XXE) Data Parsing Arbitrary File Disclosure @@ -4569,7 +4626,7 @@ 1.3.2 - + WordPress WordPress Related Posts Plugin Cross-Site Request Forgery Vulnerability @@ -4578,7 +4635,7 @@ 2.6.2 - + WordPress Related Posts Plugin Cross-Site Request Forgery Vulnerability @@ -4587,7 +4644,7 @@ 2.7.2 - + WordPress WP Print Friendly Plugin Security Bypass Vulnerability @@ -4596,7 +4653,7 @@ 0.5.3 - + WordPress Contextual Related Posts Plugin Cross-Site Request Forgery Vulnerability @@ -4605,7 +4662,7 @@ 1.8.7 - + WordPress Calendar Plugin Cross-Site Request Forgery Vulnerability @@ -4614,7 +4671,7 @@ 1.3.3 - + WordPress Feedweb Plugin 'wp_post_id' Parameter XSS @@ -4654,6 +4711,8 @@ Digg Digg CSRF http://wordpress.org/plugins/digg-digg/changelog/ + http://secunia.com/advisories/53120/ + http://osvdb.org/show/osvdb/93544 CSRF 5.3.5 @@ -4661,8 +4720,10 @@ - Vulneratbility in SS Quiz + SS Quiz Plugin Multiple Unspecified Vulnerabilities http://wordpress.org/plugins/ssquiz/changelog/ + http://secunia.com/advisories/53378/ + http://osvdb.org/show/osvdb/93531 UNKNOWN 2.0 @@ -4694,11 +4755,13 @@ 1.4.5 - + CSRF in WordPress underConstruction plugin (CVE-2013-2699) http://wordpress.org/plugins/underconstruction/changelog/ + http://secunia.com/advisories/52881/ + http://osvdb.org/show/osvdb/93857 CSRF 1.09 @@ -4707,7 +4770,9 @@ ADIF Log Search Widget XSS Arbitrary Vulnerability - http://packetstorm.interhost.co.il/1305-exploits/adif-xss.txt + http://packetstormsecurity.com/files/121777/ADIF-Log-Search-Widget-1.0e-Cross-Site-Scripting.html + http://secunia.com/advisories/53599/ + http://osvdb.org/show/osvdb/93721 XSS @@ -4746,4 +4811,62 @@ + + + Image slider with description Plugin Unspecified Vulnerability + http://secunia.com/advisories/53588/ + http://osvdb.org/show/osvdb/93691 + UNKNOWN + 7.0 + + + + + + User Role Editor Plugin Cross-Site Request Forgery Vulnerability + http://secunia.com/advisories/53593/ + http://osvdb.org/show/osvdb/93699 + http://www.exploit-db.com/exploits/25721 + CSRF + 3.14 + + + + + + EELV Newsletter Plugin Cross-Site Scripting Vulnerability + http://secunia.com/advisories/53546/ + http://osvdb.org/show/osvdb/93685 + XSS + 3.3.1 + + + + + + Frontier Post Plugin Publishing Posts Security Bypass + http://secunia.com/advisories/53474/ + http://osvdb.org/show/osvdb/93639 + UNKNOWN + + + + + + Spider Catalog Plugin Cross-Site Scripting and SQL Injection Vulnerabilities + http://secunia.com/advisories/53491/ + http://osvdb.org/show/osvdb/93591 + MULTI + + + + + + Spider Event Calendar Plugin Security Bypass, Cross-Site Scripting and SQLi Vulnerabilities + http://secunia.com/advisories/53481/ + http://osvdb.org/show/osvdb/93584 + MULTI + + + diff --git a/data/wp_vulns.xml b/data/wp_vulns.xml index 497a859a..c8cb1e77 100644 --- a/data/wp_vulns.xml +++ b/data/wp_vulns.xml @@ -7,6 +7,8 @@ CVE-2013-2173: WordPress 3.5.1 DoS in class-phpass.php http://seclists.org/fulldisclosure/2013/Jun/65 + http://secunia.com/advisories/53676/ + http://osvdb.org/show/osvdb/94235 UNKNOWN