From 40f96dd2bde8ed262c6d9428734624510a93fad4 Mon Sep 17 00:00:00 2001 From: Peter Date: Thu, 12 Dec 2013 13:30:32 +0100 Subject: [PATCH] Update plugin_vulns.xml --- data/plugin_vulns.xml | 60 ++++++++++++++++++++++++++++++++++++++++--- 1 file changed, 57 insertions(+), 3 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 6ca1c73a..e20defa9 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -2790,7 +2790,7 @@ - Count per Day 3.2.5 - /wp-content/wp-admin/index.php daytoshow Parameter XSS + Count per Day 3.2.5 - wp-admin/index.php daytoshow Parameter XSS 90893 52436 @@ -8195,7 +8195,7 @@ - Spider Video Player 2.1 - /wp-content/plugins/player/settings.php theme Parameter SQL Injection + Spider Video Player 2.1 - settings.php theme Parameter SQL Injection 92264 2013-3532 @@ -8205,11 +8205,19 @@ SQLI + + Spider Video Player 2.1 - settings.php s_v_player_id Parameter Reflected XSS + + 100848 + http://packetstormsecurity.com/files/124353/ + + XSS + - Finalist - /wp-content/plugins/finalist/vote.php id Parameter Reflected XSS + Finalist - vote.php id Parameter Reflected XSS 98665 http://packetstormsecurity.com/files/123597/ @@ -8855,6 +8863,7 @@ Js-Multi-Hotel 2.2.1 - refreshDate.php roomid Parameter Reflected XSS 100575 + 55919 http://packetstormsecurity.com/files/124239/ http://www.securityfocus.com/bid/64045 @@ -8900,4 +8909,49 @@ + + + TDO Mini Forms 0.13.9 - tdomf-upload-inline.php File Upload Remote Code Execution + + 100847 + http://packetstormsecurity.com/files/124352/ + + RCE + + + + + + HuskerPortfolio 0.3 - huskerPortfolio.php File Upload CSRF + + 100845 + http://packetstormsecurity.com/files/124359/ + + CSRF + + + + + + FormCraft - form.php id Parameter SQL Injection + + 100877 + 56044 + http://packetstormsecurity.com/files/124343/ + + SQLI + + + + + + PhotoSmash Galleries 1.0.7 - bwbps-uploader.php File Upload Remote Code Execution + + 100878 + http://packetstormsecurity.com/files/124342/ + + RCE + + +