From 1f2588d677cfb5e3b3233861bc273425089bc7fd Mon Sep 17 00:00:00 2001 From: Peter Date: Wed, 12 Feb 2014 10:16:02 +0100 Subject: [PATCH] Update vuln db --- data/plugin_vulns.xml | 27 +++++++++++++++++++++++++++ data/theme_vulns.xml | 22 ++++++++++++++++++++++ 2 files changed, 49 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index f75198f3..84dbb07a 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -10811,6 +10811,33 @@ AUTHBYPASS 1.3.2 + + Delightful Downloads 1.3.1.1 - includes/functions.php User-Agent HTTP Header Stored XSS + + 102928 + + XSS + 1.3.2 + + + + + + Mobiloud 1.9.0 - comments/disqus_count.php shortname Parameter Reflected XSS + + 102898 + + XSS + 1.9.1 + + + Mobiloud 1.9.0 - comments/disqus.php shortname Parameter Reflected XSS + + 102899 + + XSS + 1.9.1 + diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index b486b0fc..d53cfc24 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -1987,6 +1987,7 @@ Persuasion <= 2.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download 101331 + 56359 30443 http://packetstormsecurity.com/files/124547/ http://www.securityfocus.com/bid/64501 @@ -2435,6 +2436,7 @@ Highlight Powerful Premium - upload-handler.php File Upload CSRF 99703 + 55671 29525 http://packetstormsecurity.com/files/123974/ @@ -2707,6 +2709,7 @@ DejaVu 2.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download 101331 + 56359 30443 http://www.securityfocus.com/bid/64501 @@ -2730,6 +2733,7 @@ Elegance 2.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download 101331 + 56359 30443 http://www.securityfocus.com/bid/64501 @@ -2753,6 +2757,7 @@ Echelon 2.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download 101331 + 56359 30443 http://www.securityfocus.com/bid/64501 @@ -2776,6 +2781,7 @@ Modular 2.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download 101331 + 56359 30443 http://www.securityfocus.com/bid/64501 @@ -2799,6 +2805,7 @@ Fusion 2.1 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download 101331 + 56359 30443 http://www.securityfocus.com/bid/64501 @@ -2822,6 +2829,7 @@ Method 2.1 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download 101331 + 56359 30443 http://www.securityfocus.com/bid/64501 @@ -2845,6 +2853,7 @@ Myriad 2.0 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download 101331 + 56359 30443 http://www.securityfocus.com/bid/64501 @@ -2868,6 +2877,7 @@ Construct 1.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download 101331 + 56359 30443 http://www.securityfocus.com/bid/64501 @@ -2891,6 +2901,7 @@ Awake 3.3 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download 101331 + 56359 30443 http://www.securityfocus.com/bid/64501 @@ -2922,6 +2933,7 @@ InFocus 3.3 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download 101331 + 56359 30443 http://www.securityfocus.com/bid/64501 @@ -2987,4 +2999,14 @@ + + + Kiddo - remote shell upload vulnerability + + http://packetstormsecurity.com/files/125138/ + + RCE + + +