diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index fe8d08b6..2165a402 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -33,6 +33,109 @@ ryandewhurst at gmail --> + + + Crayon Syntax Highlighter Remote File Inclusion + http://secunia.com/advisories/50804/ + http://ceriksen.com/2012/10/15/wordpress-crayon-syntax-highlighter-remote-file-inclusion-vulnerability/ + RFI + + + + + + UnGallery Arbitrary Command Execution + http://secunia.com/advisories/50875/ + http://ceriksen.com/2012/10/23/wordpress-ungallery-remote-command-injection-vulnerability/ + RCE + + + + + + Thank You Counter Button XSS + http://secunia.com/advisories/50977/ + XSS + + + + + + Bookings XSS + http://secunia.com/advisories/50975/ + XSS + + + + + + Cimy User Manager Arbitrary File Disclosure + http://secunia.com/advisories/50834/ + http://ceriksen.com/2012/10/24/wordpress-cimy-user-manager-arbitrary-file-disclosure/ + UNKNOWN + + + + + + FireStorm Professional Real Estate Plugin Multiple SQL Injection + http://secunia.com/advisories/50873/ + http://ceriksen.com/2012/10/25/wordpress-firestorm-professional-real-estate-plugin-sql-injection-vulnerability/ + SQLI + + + + + + WP125 Multiple XSS + http://secunia.com/advisories/50976/ + XSS + + + + + + All Video Gallery + http://secunia.com/advisories/50874/ + http://ceriksen.com/2012/11/04/wordpress-all-video-gallery-plugin-sql-injection/ + SQLI + + + + + + BuddyStream XSS + http://secunia.com/advisories/50972/ + XSS + + + + + + post-views XSS + http://secunia.com/advisories/50982/ + XS + + + + + + Floating Social Media Links Remote File Inclusion + http://secunia.com/advisories/51346/ + http://ceriksen.com/2013/01/12/wordpress-floating-social-media-link-plugins-remote-file-inclusion/ + RFI + + + + + + Zingiri Forum Arbitrary File Disclosure + http://secunia.com/advisories/50833/ + http://ceriksen.com/2013/01/12/wordpress-zingiri-forums-arbitrary-file-disclosure/ + UNKNOWN + + + Google Document Embedder Arbitrary File Disclosure diff --git a/data/plugins.txt b/data/plugins.txt index 0d35160c..d9995457 100644 --- a/data/plugins.txt +++ b/data/plugins.txt @@ -242,6 +242,7 @@ buddypress-sliding-login-panel/Thumbs.db buddypress-toolbar/buddypress-toolbar.php buddypress-xprofile-custom-fields-type/bp-xprofile-custom-fields-type.php buddypress/readme.txt +buddystream/readme.txt bulk-comment-remove/Bulk_Comment_Removal.php bulk-delete/bulk-delete.php bulk-watermark/bulk-watermark.php @@ -300,6 +301,7 @@ child-pages-shortcode/child-pages-shortcode.php child-themify/child-themify.php cimy-header-image-rotator/README_OFFICIAL.txt cimy-user-extra-fields/README_OFFICIAL.txt +cimy-user-manager/README_OFFICIAL.txt ckeditor-for-wordpress/ckeditor.config.js clean-options/cleanoptions.php cleaner-gallery/admin.css @@ -1589,6 +1591,7 @@ testimonial-rotator/jquery.cycle.all.js testimonials-by-woothemes/readme.txt testimonials-widget/readme.txt thank-me-later/Message.php +thanks-you-counter-button/thankyou.js the-events-calendar-category-colors/category-colors-settings.php the-events-calendar/readme.txt the-future-is-now/future-post.php @@ -1684,6 +1687,7 @@ ultimate-tinymce/__dev_notes.txt ultimate-twitter-profile-widget/jscolor.js unconfirmed/readme.txt underconstruction/ajax-loader.gif +ungallery/banner.txt unique-headers/index.php unpointzero-slider/COPYING.txt updraftplus/example-decrypt.php