From 2472e5546f238b282dd6aecc7dcadbec4cfaa4f1 Mon Sep 17 00:00:00 2001 From: Peter Date: Thu, 2 Jan 2014 12:02:05 +0100 Subject: [PATCH] Update plugin_vulns.xml --- data/plugin_vulns.xml | 58 ++++++++++++++++++++++++++++++++++++++++--- 1 file changed, 54 insertions(+), 4 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 315ccaee..8aeda6b2 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -6679,19 +6679,25 @@ snazzy-archives <= 1.7.1 - XSS vulnerability - http://www.openwall.com/lists/oss-security/2013/03/10/3 + 91128 2009-4168 + 52527 + http://www.openwall.com/lists/oss-security/2013/03/10/3 XSS + 1.7.2 - vkontakte-api - XSS vulnerability + vkontakte-api - vkontakte-api/swf/tagcloud.swf tagcloud Parameter XSS - http://www.openwall.com/lists/oss-security/2013/03/11/1 + 91128 2009-4168 + 52539 + http://seclists.org/oss-sec/2013/q1/616 + http://www.openwall.com/lists/oss-security/2013/03/11/1 XSS @@ -6801,13 +6807,46 @@ - Backupbuddy - sensitive data exposure in importbuddy.php + Backupbuddy - importbuddy.php Direct Request Remote Backup File Disclosure + 91631 + 2013-2741 + http://packetstormsecurity.com/files/120923/ + http://seclists.org/fulldisclosure/2013/Mar/206 + + AUTHBYPASS + + + Backupbuddy - importbuddy.php step Parameter Manipulation Authentication Bypass + + 91890 + 2013-2743 + http://packetstormsecurity.com/files/120923/ + http://seclists.org/fulldisclosure/2013/Mar/206 + + AUTHBYPASS + + + Backupbuddy - importbuddy.php step Parameter Remote PHP Information Disclosure + + 91891 + 2013-2744 + http://packetstormsecurity.com/files/120923/ http://seclists.org/fulldisclosure/2013/Mar/206 http://archives.neohapsis.com/archives/fulldisclosure/2013-03/0205.html UNKNOWN + + Backupbuddy - importbuddy.php Restore Operation Persistence Weakness + + 91892 + 2013-2742 + http://packetstormsecurity.com/files/120923/ + http://seclists.org/fulldisclosure/2013/Mar/206 + + AUTHBYPASS + @@ -9525,4 +9564,15 @@ + + + Amazon Affiliate Link Localizer 1.8.2 - amazon_affiliate_link_localizer.php amzn_com Parameter XSS + + 100783 + http://www.dfcode.org/code.php?id=27 + + XSS + + +