From c7c1c1d3e7b65d72a943519d68346f5ff99b1368 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Wed, 23 Oct 2013 22:06:25 +0200 Subject: [PATCH 1/3] Update plugin_vulns.xml --- data/plugin_vulns.xml | 30 ++++++++++++++++++++++++++---- 1 file changed, 26 insertions(+), 4 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index b7c22845..ef4d7ac5 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -1037,11 +1037,14 @@ MULTI - Wordfence 3.8.1 - XSS + Wordfence 3.8.1 - wp-admin/admin.php whois Parameter Stored XSS + 97884 http://packetstormsecurity.com/files/122993/ + http://www.securityfocus.com/bid/62053 XSS + 3.8.3 @@ -6371,13 +6374,21 @@ - wordpress-seo - Security issue which allowed any user to reset settings + WordPress SEO - Security issue which allowed any user to reset settings http://wordpress.org/plugins/wordpress-seo/changelog/ UNKNOWN 1.4.5 + + WordPress SEO 1.14.15 - index.php s Parameter Reflected XSS + + 97885 + http://packetstormsecurity.com/files/123028/ + + XSS + @@ -6817,10 +6828,12 @@ Design Approval System 3.6 - XSS Vulnerability + 97192 + 97279 + 54704 http://seclists.org/bugtraq/2013/Sep/54 http://packetstormsecurity.com/files/123227/ 2013-5711 - 97279 3.7 XSS @@ -7071,8 +7084,17 @@ - Encrypted Blog 0.0.6.2 - XSS, Open Redirect + Encrypted Blog 0.0.6.2 - encrypt_blog_form.php redirect_to Parameter Arbitrary Site Redirect + 97881 + http://packetstormsecurity.com/files/122992/ + + UNKNOWN + + + Encrypted Blog 0.0.6.2 - encrypt_blog_form.php redirect_to Parameter Reflected XSS + + 97882 http://packetstormsecurity.com/files/122992/ XSS From 32588554da07a90fcd2655006082d949fb25db58 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Wed, 23 Oct 2013 22:40:37 +0200 Subject: [PATCH 2/3] Update plugin_vulns.xml --- data/plugin_vulns.xml | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index ef4d7ac5..f34b7570 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -7281,6 +7281,14 @@ + + A Forms 1.4.0 Multiple Parameters SQL Injection + + 96404 + + SQLI + 1.4.2 + A Forms 1.4.1 - Form Submission CSRF 96381 @@ -7520,4 +7528,17 @@ + + + Really simple Facebook Twitter share buttons 2.10.4 - Settings Page Manipulation CSRF + + 97190 + 54707 + http://www.securityfocus.com/bid/62268 + + CSRF + 2.10.5 + + + From 9f06b61e9fe946e5b2aa635e1223cacf097fd131 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Wed, 23 Oct 2013 22:51:08 +0200 Subject: [PATCH 3/3] Update plugin_vulns.xml --- data/plugin_vulns.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index f34b7570..0c4b06e2 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -7280,7 +7280,6 @@ - A Forms 1.4.0 Multiple Parameters SQL Injection @@ -7289,6 +7288,7 @@ SQLI 1.4.2 + A Forms 1.4.1 - Form Submission CSRF 96381