Update theme_vulns.xml
This commit is contained in:
@@ -1963,6 +1963,28 @@
|
|||||||
</references>
|
</references>
|
||||||
<type>XSS</type>
|
<type>XSS</type>
|
||||||
</vulnerability>
|
</vulnerability>
|
||||||
|
<vulnerability>
|
||||||
|
<title>Persuasion <= 2.4 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101330</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.5</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
<vulnerability>
|
||||||
|
<title>Persuasion <= 2.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101331</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.5</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
</theme>
|
</theme>
|
||||||
|
|
||||||
<theme name="More">
|
<theme name="More">
|
||||||
@@ -2634,4 +2656,254 @@
|
|||||||
</vulnerability>
|
</vulnerability>
|
||||||
</theme>
|
</theme>
|
||||||
|
|
||||||
|
<theme name="dejavu">
|
||||||
|
<vulnerability>
|
||||||
|
<title>DejaVu 2.4 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101330</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.5</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
<vulnerability>
|
||||||
|
<title>DejaVu 2.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101331</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.5</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
</theme>
|
||||||
|
|
||||||
|
<theme name="elegance">
|
||||||
|
<vulnerability>
|
||||||
|
<title>Elegance 2.4 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101330</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.5</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
<vulnerability>
|
||||||
|
<title>Elegance 2.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101331</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.5</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
</theme>
|
||||||
|
|
||||||
|
<theme name="echelon">
|
||||||
|
<vulnerability>
|
||||||
|
<title>Echelon 2.4 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101330</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.5</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
<vulnerability>
|
||||||
|
<title>Echelon 2.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101331</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.5</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
</theme>
|
||||||
|
|
||||||
|
<theme name="modular">
|
||||||
|
<vulnerability>
|
||||||
|
<title>Modular 2.4 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101330</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.5</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
<vulnerability>
|
||||||
|
<title>Modular 2.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101331</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.5</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
</theme>
|
||||||
|
|
||||||
|
<theme name="fusion">
|
||||||
|
<vulnerability>
|
||||||
|
<title>Fusion 2.1 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101330</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.2</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
<vulnerability>
|
||||||
|
<title>Fusion 2.1 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101331</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.2</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
</theme>
|
||||||
|
|
||||||
|
<theme name="method">
|
||||||
|
<vulnerability>
|
||||||
|
<title>Method 2.1 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101330</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.5</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
<vulnerability>
|
||||||
|
<title>Method 2.1 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101331</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.2</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
</theme>
|
||||||
|
|
||||||
|
<theme name="myriad">
|
||||||
|
<vulnerability>
|
||||||
|
<title>Myriad 2.0 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101330</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.5</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
<vulnerability>
|
||||||
|
<title>Myriad 2.0 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101331</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.1</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
</theme>
|
||||||
|
|
||||||
|
<theme name="construct">
|
||||||
|
<vulnerability>
|
||||||
|
<title>Construct 1.4 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101330</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.5</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
<vulnerability>
|
||||||
|
<title>Construct 1.4 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101331</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>1.5</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
</theme>
|
||||||
|
|
||||||
|
<theme name="awake">
|
||||||
|
<vulnerability>
|
||||||
|
<title>Awake 3.3 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101330</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.5</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
<vulnerability>
|
||||||
|
<title>Awake 3.3 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101331</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>3.4</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
</theme>
|
||||||
|
|
||||||
|
<theme name="infocus">
|
||||||
|
<vulnerability>
|
||||||
|
<title>InFocus 3.3 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101330</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>2.5</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
<vulnerability>
|
||||||
|
<title>InFocus 3.3 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>101331</osvdb>
|
||||||
|
<exploitdb>30443</exploitdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/124547/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/64501</url>
|
||||||
|
</references>
|
||||||
|
<type>UNKNOWN</type>
|
||||||
|
<fixed_in>3.4</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
</theme>
|
||||||
|
|
||||||
</vulnerabilities>
|
</vulnerabilities>
|
||||||
|
|||||||
Reference in New Issue
Block a user