Update vuln db

This commit is contained in:
Peter
2014-06-10 08:47:25 +02:00
parent 7748019a76
commit 1ee14f4c69

View File

@@ -10656,11 +10656,48 @@
<type>FPD</type>
</vulnerability>
<vulnerability>
<title>DZS Video Gallery - Flash Files Content Spoofing &amp; Cross-Site Scripting</title>
<title>DZS Video Gallery - preview_allchars.swf logoLink Parameter Reflected XSS</title>
<references>
<osvdb>107521</osvdb>
<cve>2014-3923</cve>
<url>http://packetstormsecurity.com/files/126846/</url>
<url>http://www.securityfocus.com/bid/67698</url>
<url>http://seclists.org/fulldisclosure/2014/May/157</url>
</references>
<type>MULTI</type>
<type>XSS</type>
</vulnerability>
<vulnerability>
<title>DZS Video Gallery - deploy/preview_skin_overlay.swf logoLink Parameter Reflected XSS</title>
<references>
<osvdb>107522</osvdb>
<cve>2014-3923</cve>
<url>http://packetstormsecurity.com/files/126846/</url>
<url>http://www.securityfocus.com/bid/67698</url>
<url>http://seclists.org/fulldisclosure/2014/May/157</url>
</references>
<type>XSS</type>
</vulnerability>
<vulnerability>
<title>DZS Video Gallery - deploy/preview.swf logoLink Parameter Reflected XSS</title>
<references>
<osvdb>107523</osvdb>
<cve>2014-3923</cve>
<url>http://packetstormsecurity.com/files/126846/</url>
<url>http://www.securityfocus.com/bid/67698</url>
<url>http://seclists.org/fulldisclosure/2014/May/157</url>
</references>
<type>XSS</type>
</vulnerability>
<vulnerability>
<title>DZS Video Gallery - preview_skin_rouge.swf logoLink Parameter Reflected XSS</title>
<references>
<osvdb>107524</osvdb>
<cve>2014-3923</cve>
<url>http://packetstormsecurity.com/files/126846/</url>
<url>http://www.securityfocus.com/bid/67698</url>
<url>http://seclists.org/fulldisclosure/2014/May/157</url>
</references>
<type>XSS</type>
</vulnerability>
</plugin>
@@ -12078,6 +12115,14 @@
</plugin>
<plugin name="blogvault-real-time-backup">
<vulnerability>
<title>blogVault 1.08 - Missing Account Empty Secret Key Generation</title>
<references>
<osvdb>107570</osvdb>
</references>
<type>BYPASS</type>
<fixed_in>1.09</fixed_in>
</vulnerability>
<vulnerability>
<title>blogVault 1.05 - admin.php blogVault Key Setting CSRF</title>
<references>