diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index ba1cffed..f088fc03 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -10656,11 +10656,48 @@ FPD - DZS Video Gallery - Flash Files Content Spoofing & Cross-Site Scripting + DZS Video Gallery - preview_allchars.swf logoLink Parameter Reflected XSS + 107521 + 2014-3923 + http://packetstormsecurity.com/files/126846/ + http://www.securityfocus.com/bid/67698 http://seclists.org/fulldisclosure/2014/May/157 - MULTI + XSS + + + DZS Video Gallery - deploy/preview_skin_overlay.swf logoLink Parameter Reflected XSS + + 107522 + 2014-3923 + http://packetstormsecurity.com/files/126846/ + http://www.securityfocus.com/bid/67698 + http://seclists.org/fulldisclosure/2014/May/157 + + XSS + + + DZS Video Gallery - deploy/preview.swf logoLink Parameter Reflected XSS + + 107523 + 2014-3923 + http://packetstormsecurity.com/files/126846/ + http://www.securityfocus.com/bid/67698 + http://seclists.org/fulldisclosure/2014/May/157 + + XSS + + + DZS Video Gallery - preview_skin_rouge.swf logoLink Parameter Reflected XSS + + 107524 + 2014-3923 + http://packetstormsecurity.com/files/126846/ + http://www.securityfocus.com/bid/67698 + http://seclists.org/fulldisclosure/2014/May/157 + + XSS @@ -12078,6 +12115,14 @@ + + blogVault 1.08 - Missing Account Empty Secret Key Generation + + 107570 + + BYPASS + 1.09 + blogVault 1.05 - admin.php blogVault Key Setting CSRF