From 32e590f398a44ef651efffbff25cfc1a32c10756 Mon Sep 17 00:00:00 2001 From: Peter Date: Wed, 11 Dec 2013 07:50:04 +0100 Subject: [PATCH] Update wp_vulns.xml --- data/wp_vulns.xml | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/data/wp_vulns.xml b/data/wp_vulns.xml index fc0702a1..1e10cbb3 100644 --- a/data/wp_vulns.xml +++ b/data/wp_vulns.xml @@ -94,7 +94,7 @@ 3.5.2 - WordPress 3.4 - 3.5.1 DoS in class-phpass.php + WordPress 3.4-3.5.1 DoS in class-phpass.php http://seclists.org/fulldisclosure/2013/Jun/65 53676 @@ -112,6 +112,7 @@ 94790 XSS + 3.5.2 WordPress TinyMCE Plugin Flash Applet Unspecified Spoofing Weakness @@ -119,6 +120,7 @@ 94787 UNKNOWN + 3.5.2 WordPress File Upload Unspecified Path Disclosure @@ -126,27 +128,31 @@ 94788 UNKNOWN + 3.5.2 - WordPress oEmbed Unspecified XML External Entity (XXE) Arbitrary File Disclosure + WordPress 3.5-3.5.1 oEmbed Unspecified XML External Entity (XXE) Arbitrary File Disclosure 94789 XXE + 3.5.2 - WordPress Multiple Role Remote Privilege Escalation + WordPress 3.5-3.5.1 Multiple Role Remote Privilege Escalation 94783 UNKNOWN + 3.5.2 - WordPress HTTP API Unspecified Server Side Request Forgery (SSRF) + WordPress 3.5-3.5.1 HTTP API Unspecified Server Side Request Forgery (SSRF) 94784 SSRF + 3.5.2