diff --git a/README.md b/README.md index a14ff925..f417daca 100644 --- a/README.md +++ b/README.md @@ -28,6 +28,7 @@ WPScan comes pre-installed on the following Linux distributions: - [BackBox Linux](http://www.backbox.org/) - [BackTrack Linux](http://www.backtrack-linux.org/) +- [Kali Linux](http://www.kali.org/) - [Pentoo](http://www.pentoo.ch/) - [SamuraiWTF](http://samurai.inguardians.com/) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 7f287eb3..1c5fcdbf 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -275,12 +275,15 @@ - Google Document Embedder Arbitrary File Disclosure + Google Document Embedder - Arbitrary File Disclosure + 2012-4915 23970 + 50832 + http://www.securityfocus.com/bid/57133 + http://packetstormsecurity.com/files/119329/ http://ceriksen.com/2013/01/03/wordpress-google-document-embedder-arbitrary-file-disclosure/ - 50832 exploit/unix/webapp/wp_google_document_embedder_exec UNKNOWN @@ -448,17 +451,23 @@ - ReFlex Gallery Shell Upload + ReFlex Gallery 1.3 - Shell Upload http://packetstormsecurity.com/files/119218/ UPLOAD + + ReFlex Gallery 1.4 - reflex-gallery.php Direct Request Path Disclosure + + 88869 + + - Uploader 1.0.4 Shell Upload + Uploader 1.0.4 - Shell Upload http://packetstormsecurity.com/files/119219/ @@ -468,7 +477,7 @@ - Xerte Online 0.32 Shell Upload + Xerte Online 0.32 - Shell Upload http://packetstormsecurity.com/files/119220/ diff --git a/data/wp_vulns.xml b/data/wp_vulns.xml index ddb44cc2..32eed501 100644 --- a/data/wp_vulns.xml +++ b/data/wp_vulns.xml @@ -16,6 +16,7 @@ 97211 UNKNOWN + 3.6.1 wp-includes/functions.php get_allowed_mime_types Function SWF / EXE File Upload XSS Weakness @@ -35,6 +36,7 @@ http://core.trac.wordpress.org/changeset/25323 UNKNOWN + 3.6.1 wp-admin/includes/post.php user_ID Parameter Manipulation Post Authorship Spoofing @@ -45,6 +47,7 @@ http://core.trac.wordpress.org/changeset/25321 UNKNOWN + 3.6.1 wp-includes/functions.php get_allowed_mime_types Function HTML File Upload XSS Weakness @@ -2090,9 +2093,19 @@ Wordpress <= 1.5.1.2 xmlrpc Interface SQL Injection Exploit + 17636 + 17637 + 17638 + 17639 + 17640 + 17641 + 2005-2108 1077 + 15831 + 15898 SQLI + 1.5.1.3 XMLRPC Pingback API Internal/External Port Scanning @@ -2158,4 +2171,56 @@ + + + WordPress wp-trackback.php tb_id Parameter SQL Injection + + 2005-1687 + 16701 + 16702 + 16703 + + SQLI + 1.5.1 + + + WordPress post.php p Parameter XSS + + 16702 + 16701 + 16703 + + XSS + 1.5.1 + + + WordPress Multiple Script Direct Request Path Disclosure + + 2005-1688 + 16703 + 16701 + 16702 + + UNKNOWN + 1.5.1 + + + WordPress Cross-Site Scripting and SQL Injection Vulnerabilities + + 16478 + 15324 + + MULTI + 1.5.1 + + + WordPress template-functions-post.php Multiple Field XSS + + 2005-1102 + 15643 + + XSS + + +