From 17fec7a16106fe605e958c419622e892c189b51e Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Tue, 5 Nov 2013 11:31:42 +0100 Subject: [PATCH] Update plugin_vulns.xml --- data/plugin_vulns.xml | 19 +++++++++++++++---- 1 file changed, 15 insertions(+), 4 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index d6278bc5..71114a2f 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -593,11 +593,12 @@ - SWF Vulnerable to XSS Bundled in Many WordPress Plugins + Comment Extra Field 1.7 - CSRF / XSS + http://packetstormsecurity.com/files/122625/ http://brindi.si/g/blog/vulnerable-swf-bundled-in-wordpress-plugins.html - XSS + MULTI @@ -5883,8 +5884,10 @@ - Terillion Reviews - Cross Site Scripting + Terillion Reviews - Profile Id Field XSS + 91123 + 2013-1201 http://packetstormsecurity.com/files/120730/ XSS @@ -6702,6 +6705,7 @@ Xorbin Digital Flash Clock 1.0 - Flash-based XSS + http://packetstormsecurity.com/files/122223/ http://advisory.prakharprasad.com/xorbin_dfc_wp.txt 2013-4693 @@ -6779,6 +6783,7 @@ 95557 26804 + http://packetstormsecurity.com/files/122396/ RFI @@ -7253,8 +7258,10 @@ Booking Calendar 4.1.4 - CSRF Vulnerability - 27399 96088 + 27399 + 54461 + http://packetstormsecurity.com/files/122691/ http://wpbookingcalendar.com/ CSRF @@ -7280,10 +7287,12 @@ 98279 28808 + 55172 http://packetstormsecurity.com/files/123549/ http://quick-plugins.com/quick-contact-form/ XSS + 6.1 @@ -7616,6 +7625,7 @@ Feed - news_dt.php nid Parameter SQL Injection 94804 + http://packetstormsecurity.com/files/122260/ SQLI @@ -7772,6 +7782,7 @@ 98831 2013-6281 55396 + http://packetstormsecurity.com/files/123699/ http://www.securityfocus.com/bid/63256 XSS