From fed48e6c7688ac8ee71651aec81364be4d697599 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Wed, 9 Oct 2013 18:20:43 +0200 Subject: [PATCH 1/4] Update plugin_vulns.xml --- data/plugin_vulns.xml | 19 ++++++++++++++++--- 1 file changed, 16 insertions(+), 3 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 1033d647..0ee20eae 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -1043,8 +1043,11 @@ - BBPress SQL Injection / Path Disclosure + BBPress - SQL Injection / Path Disclosure + 22396 + 86400 + http://xforce.iss.net/xforce/xfdb/78244 http://packetstormsecurity.com/files/116123/ MULTI @@ -1607,6 +1610,9 @@ Font Uploader 1.2.4 Arbitrary File Upload 18994 + 82657 + 2012-3814 + http://www.securityfocus.com/bid/53853 UPLOAD @@ -1656,9 +1662,10 @@ - HTML5 AV Manager 0.2.7 Arbitrary File Upload + HTML5 AV Manager 0.2.7 - Arbitrary File Upload 18990 + http://www.securityfocus.com/bid/53804 UPLOAD @@ -1868,6 +1875,8 @@ LeagueManager v3.8 SQL Injection 24789 + 2013-1852 + 91442 SQLI @@ -4620,8 +4629,10 @@ - WordPress SolveMedia CSRF Vulnerability + SolveMedia 1.1.0 - CSRF Vulnerability + 24364 + 89585 http://1337day.com/exploit/20222 51927 @@ -5720,6 +5731,8 @@ Mathjax Latex 1.1 CSRF Vulnerability + 24889 + 91737 http://1337day.com/exploit/20566 CSRF From c6cae028e4afb8d873ad9b42e4f2b091686fa309 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Wed, 9 Oct 2013 23:25:15 +0200 Subject: [PATCH 2/4] Update plugin_vulns.xml --- data/plugin_vulns.xml | 74 +++++++++++++++++++++++++++++++++++++++++-- 1 file changed, 72 insertions(+), 2 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 0ee20eae..2b72de98 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -2003,12 +2003,23 @@ - BulletProof Security <= 0.47 Cross Site Scripting + BulletProof Security <= 0.47 - Cross Site Scripting http://packetstormsecurity.com/files/112618/ XSS + + BulletProof Security - Security Log Script Insertion Vulnerability + + 95928 + 95929 + 95930 + 2013-3487 + 53614 + + 0.49 + @@ -6570,10 +6581,12 @@ - CSRF in sexybookmarks + SexyBookmarks - Setting Manipulation CSRF http://wordpress.org/plugins/sexybookmarks/changelog/ + 95908 2013-3256 + 53138 CSRF 6.1.5.0 @@ -7003,4 +7016,61 @@ + + + Booking System - events_facualty_list.php eid Parameter Reflected XSS + + 96740 + + XSS + + + + + + JS Restaurant - popup.php restuarant_id Parameter SQL Injection + + 96743 + http://packetstormsecurity.com/files/122316/ + + SQLI + + + + + + FlagEm Plugin - flagit.php cID Parameter XSS + + 98226 + http://www.securityfocus.com/bid/61401 + http://xforce.iss.net/xforce/xfdb/85925 + http://packetstormsecurity.com/files/122505/ + + XSS + + + + + + Chat - message Parameter XSS + + 95984 + 54403 + + XSS + + + + + + Shareaholic - Unspecified CSRF + + 96321 + 54529 + + CSRF + 7.0.3.4/fixed_in> + + + From 3e3f11a2734d7f2a9da64302642780b578653b33 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Thu, 10 Oct 2013 09:40:48 +0200 Subject: [PATCH 3/4] Update plugin_vulns.xml --- data/plugin_vulns.xml | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 2b72de98..094ae452 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -6806,7 +6806,19 @@ WP Ultimate Email Marketer - Multiple Vulnerabilities + 97648 + 97649 + 97650 + 97651 + 97652 + 97653 + 97654 + 97655 + 97656 + 2013-3263 + 2013-3264 53170 + http://www.securityfocus.com/bid/62621 MULTI @@ -6982,6 +6994,7 @@ Quick Contact Form Plugin 6.0 - Persistent XSS 28808 + http://packetstormsecurity.com/files/123549/ http://quick-plugins.com/quick-contact-form/ XSS @@ -7073,4 +7086,14 @@ + + + Page Showcaser Boxes - Title Field Stored XSS + + 97579 + + XSS + + + From 7549d3778ca1f185b54799879b3ef1dd25991f9b Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Thu, 10 Oct 2013 09:49:10 +0200 Subject: [PATCH 4/4] Fixed a 'crucial typo' --- data/plugin_vulns.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 094ae452..7f287eb3 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -7082,7 +7082,7 @@ 54529 CSRF - 7.0.3.4/fixed_in> + 7.0.3.4