diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 68dfc20c..b1daa79b 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -2144,7 +2144,7 @@ 3.5.4 - Better WP Security v3.4.3 - Multiple XSS + Better WP Security 3.4.3 - Multiple XSS http://seclists.org/bugtraq/2012/Oct/9 @@ -2584,6 +2584,22 @@ + + Link Library 5.0.8 - wp-content/plugins/link-library/tracker.php id Parameter XSS + + 74561 + 45588 + + XSS + + + Link Library 5.0.8 - wp-content/plugins/link-library/tracker.php id Parameter SQL Injection + + 74562 + 45588 + + SQLI + Link Library <= 5.2.1 - SQL Injection @@ -4106,6 +4122,15 @@ + + WP e-Commerce 3.8.6 - wpsc-cart_widget.php cart_messages Parameter XSS + + 74295 + 45513 + + XSS + 3.8.8 + WP e-Commerce <= 3.8.6 - SQL Injection Vulnerability @@ -4114,7 +4139,7 @@ SQLI - WP-e-Commerce v3.8.9.5 - Cross Site Scripting Vulnerability + WP-e-Commerce 3.8.9.5 - Cross Site Scripting Vulnerability http://1337day.com/exploit/20517 @@ -8119,4 +8144,61 @@ + + + Social Slider <= 5.6.5 - social-slider-2/ajax.php rA Parameter SQL Injection + + 74421 + 45549 + 17617 + + SQLI + 6.0.0 + + + + + + Redirection - wp-admin/tools.php id Parameter XSS + + 74783 + 45782 + + XSS + 2.2.9 + + + + + + eShop - wp-admin/admin.php Multiple Parameter XSS + + 74464 + 45553 + http://seclists.org/bugtraq/2011/Aug/52 + + XSS + 6.2.9 + + + + + + All in One Adsense YPN 2.0.1 - all-in-one-adsense-and-ypn.php Unspecified XSS + + 74900 + 45579 + + XSS + + + All in One Adsense YPN 2.0.1 - all-in-one-adsense-and-ypn.php Direct Request AdSense Account Manipulation + + 74899 + 45579 + + XSS + + +