From c00576e06deacc34d9e70f064f2e4909a4786fd5 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Mon, 11 Nov 2013 12:55:28 +0100 Subject: [PATCH 1/3] Added OSVDB #99485, #99515 --- data/plugin_vulns.xml | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 7fd8ff4c..5e7a223c 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -7936,11 +7936,23 @@ Polldaddy Polls and Ratings 2.0.20 - Cross-Site Request Forgery Vulnerability + 99515 55464 + http://www.securityfocus.com/bid/63557 CSRF 2.0.21 + + + Jigoshop 1.8 - Multiple Script Direct Request Path Disclosure + + 99485 + + FPD + + + From bf8b1e92fa7b88963fbeb874bae35a53775d82d3 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Mon, 11 Nov 2013 13:00:50 +0100 Subject: [PATCH 2/3] Added OSVDB #99553 --- data/theme_vulns.xml | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index 62015c25..f15da29f 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -2014,4 +2014,16 @@ + + + Kernel Theme - functions/upload-handler.php File Upload Remote Code Execution + + 99553 + 29482 + http://packetstormsecurity.com/files/123954/ + + RCE + + + From 5c93540f91e4c9bfac5c094bdf6f3555af5dfc54 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Mon, 11 Nov 2013 14:05:12 +0100 Subject: [PATCH 3/3] Update theme_vulns.xml --- data/theme_vulns.xml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index f15da29f..6fe031bb 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -2014,7 +2014,7 @@ - + Kernel Theme - functions/upload-handler.php File Upload Remote Code Execution @@ -2024,6 +2024,6 @@ RCE - +