From 097898b120cb7769de58e406989dc415d9fc3b08 Mon Sep 17 00:00:00 2001 From: Henri Salo Date: Sat, 26 Jul 2014 17:05:06 +0300 Subject: [PATCH 1/2] CVE-2011-3981/allwebmenus-wordpress-menu-plugin --- data/plugin_vulns.xml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index a3e37965..feec1ee4 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -3344,7 +3344,10 @@ AllWebMenus 1.1.3 - Remote File Inclusion + 2011-3981 + 75615 17861 + 46068 RFI From ef3ed86096a7b7fecbb32799f4201137b0e1c1bc Mon Sep 17 00:00:00 2001 From: Henri Salo Date: Sat, 26 Jul 2014 18:26:28 +0300 Subject: [PATCH 2/2] CVE-2011-4562/redirection --- data/plugin_vulns.xml | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index feec1ee4..e611b4a8 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -5903,6 +5903,7 @@ 75638 2011-4106 17872 + http://markmaunder.com/2011/08/01/zero-day-vulnerability-in-many-wordpress-themes/ UPLOAD @@ -10451,6 +10452,16 @@ XSS 2.3.4 + + Redirection - view/admin/log_item.php Non-existent Posts Referer HTTP Header XSS + + 2011-4562 + 76092 + 46310 + + XSS + 2.2.10 + Redirection - wp-admin/tools.php id Parameter XSS