diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 1033d647..7f287eb3 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -1043,8 +1043,11 @@ - BBPress SQL Injection / Path Disclosure + BBPress - SQL Injection / Path Disclosure + 22396 + 86400 + http://xforce.iss.net/xforce/xfdb/78244 http://packetstormsecurity.com/files/116123/ MULTI @@ -1607,6 +1610,9 @@ Font Uploader 1.2.4 Arbitrary File Upload 18994 + 82657 + 2012-3814 + http://www.securityfocus.com/bid/53853 UPLOAD @@ -1656,9 +1662,10 @@ - HTML5 AV Manager 0.2.7 Arbitrary File Upload + HTML5 AV Manager 0.2.7 - Arbitrary File Upload 18990 + http://www.securityfocus.com/bid/53804 UPLOAD @@ -1868,6 +1875,8 @@ LeagueManager v3.8 SQL Injection 24789 + 2013-1852 + 91442 SQLI @@ -1994,12 +2003,23 @@ - BulletProof Security <= 0.47 Cross Site Scripting + BulletProof Security <= 0.47 - Cross Site Scripting http://packetstormsecurity.com/files/112618/ XSS + + BulletProof Security - Security Log Script Insertion Vulnerability + + 95928 + 95929 + 95930 + 2013-3487 + 53614 + + 0.49 + @@ -4620,8 +4640,10 @@ - WordPress SolveMedia CSRF Vulnerability + SolveMedia 1.1.0 - CSRF Vulnerability + 24364 + 89585 http://1337day.com/exploit/20222 51927 @@ -5720,6 +5742,8 @@ Mathjax Latex 1.1 CSRF Vulnerability + 24889 + 91737 http://1337day.com/exploit/20566 CSRF @@ -6557,10 +6581,12 @@ - CSRF in sexybookmarks + SexyBookmarks - Setting Manipulation CSRF http://wordpress.org/plugins/sexybookmarks/changelog/ + 95908 2013-3256 + 53138 CSRF 6.1.5.0 @@ -6780,7 +6806,19 @@ WP Ultimate Email Marketer - Multiple Vulnerabilities + 97648 + 97649 + 97650 + 97651 + 97652 + 97653 + 97654 + 97655 + 97656 + 2013-3263 + 2013-3264 53170 + http://www.securityfocus.com/bid/62621 MULTI @@ -6956,6 +6994,7 @@ Quick Contact Form Plugin 6.0 - Persistent XSS 28808 + http://packetstormsecurity.com/files/123549/ http://quick-plugins.com/quick-contact-form/ XSS @@ -6990,4 +7029,71 @@ + + + Booking System - events_facualty_list.php eid Parameter Reflected XSS + + 96740 + + XSS + + + + + + JS Restaurant - popup.php restuarant_id Parameter SQL Injection + + 96743 + http://packetstormsecurity.com/files/122316/ + + SQLI + + + + + + FlagEm Plugin - flagit.php cID Parameter XSS + + 98226 + http://www.securityfocus.com/bid/61401 + http://xforce.iss.net/xforce/xfdb/85925 + http://packetstormsecurity.com/files/122505/ + + XSS + + + + + + Chat - message Parameter XSS + + 95984 + 54403 + + XSS + + + + + + Shareaholic - Unspecified CSRF + + 96321 + 54529 + + CSRF + 7.0.3.4 + + + + + + Page Showcaser Boxes - Title Field Stored XSS + + 97579 + + XSS + + +