From 2f76277a281d5dfca0c5a2f74978baafb26fb16c Mon Sep 17 00:00:00 2001 From: erwanlr Date: Fri, 4 Jan 2013 16:35:51 +0100 Subject: [PATCH] Added wp-useronline Persistent XSS & FPD --- data/plugin_vulns.xml | 26 +++++++++++++++++++------- 1 file changed, 19 insertions(+), 7 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index f39d668c..7d8deb72 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -30,54 +30,66 @@ ryandewhurst at gmail --> + + + WP-UserOnline Full Path Disclosure + http://seclists.org/fulldisclosure/2010/Jul/8 + FPD + + + Wp-UserOnline <= 0.62 Persistent XSS + http://seclists.org/fulldisclosure/2010/Jul/8 + XSS + + Shopping Cart 8.1.14 Shell Upload / SQL Injection http://packetstormsecurity.com/files/119217/wplevelfour-sqlshell.txt MULTI - + ReFlex Gallery <= 1.4 Shell Upload http://packetstormsecurity.com/files/119218/wpreflexgallery-shell.txt UPLOAD - + Uploader 1.0.4 Shell Upload http://packetstormsecurity.com/files/119219/wpuploader104-shell.txt UPLOAD - + Xerte Online 0.32 Shell Upload http://packetstormsecurity.com/files/119220/wpxerteonline-shell.txt UPLOAD - + Advanced Custom Fields <= 3.5.1 Remote File Inclusion http://packetstormsecurity.com/files/119221/wp_advanced_custom_fields_exec.rb.txt RFI - + Wordpress sitepress-multilingual-cms Full Path Disclosure http://1337day.com/exploit/20067 FPD - + WordPress plugin Asset manager upload.php Arbitrary Code Execution http://www.ethicalhack3r.co.uk/security/wordpress-plugin-asset-manager-upload-php-arbitrary-code-execution/ UPLOAD - +