diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index 32850206..82c22ad9 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -1963,6 +1963,28 @@ XSS + + Persuasion <= 2.4 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion + + 101330 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.5 + + + Persuasion <= 2.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download + + 101331 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.5 + @@ -2634,4 +2656,254 @@ + + + DejaVu 2.4 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion + + 101330 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.5 + + + DejaVu 2.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download + + 101331 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.5 + + + + + + Elegance 2.4 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion + + 101330 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.5 + + + Elegance 2.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download + + 101331 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.5 + + + + + + Echelon 2.4 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion + + 101330 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.5 + + + Echelon 2.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download + + 101331 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.5 + + + + + + Modular 2.4 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion + + 101330 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.5 + + + Modular 2.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download + + 101331 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.5 + + + + + + Fusion 2.1 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion + + 101330 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.2 + + + Fusion 2.1 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download + + 101331 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.2 + + + + + + Method 2.1 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion + + 101330 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.5 + + + Method 2.1 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download + + 101331 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.2 + + + + + + Myriad 2.0 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion + + 101330 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.5 + + + Myriad 2.0 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download + + 101331 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.1 + + + + + + Construct 1.4 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion + + 101330 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.5 + + + Construct 1.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download + + 101331 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 1.5 + + + + + + Awake 3.3 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion + + 101330 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.5 + + + Awake 3.3 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download + + 101331 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 3.4 + + + + + + InFocus 3.3 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion + + 101330 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 2.5 + + + InFocus 3.3 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download + + 101331 + 30443 + http://packetstormsecurity.com/files/124547/ + http://www.securityfocus.com/bid/64501 + + UNKNOWN + 3.4 + + +