diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index e31fd934..b68c9ef5 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -869,6 +869,16 @@ + + + Image Resizer - Cross Site Scripting + + http://packetstormsecurity.com/files/123651/ + + XSS + + + wp-levoslideshow - Arbitrary File Upload Vulnerability @@ -4774,13 +4784,20 @@ - WooCommerce - index.php calc_shipping_state Parameter XSS + WooCommerce 2.0.12 - index.php calc_shipping_state Parameter XSS 95480 XSS 2.0.13 + + WooCommerce 2.0.17 - Cross Site Scripting + + http://packetstormsecurity.com/files/123684/ + + XSS + @@ -7003,8 +7020,9 @@ - NOSpamPTI 2.1 - Blind SQL Injection + NOSpamPTI 2.1 - wp-comments-post.php comment_post_ID Parameter SQL Injection + 97528 28485 2013-5917 http://packetstormsecurity.com/files/123331/ @@ -7114,6 +7132,18 @@ + + + Quick Paypal Payments 3.0 - Payment Sending Multiple Parameter XSS + + 98715 + 55292 + http://packetstormsecurity.com/files/123662/ + + XSS + + + Email Newsletter 8.0 - 'option' Parameter Information Disclosure Vulnerability @@ -7369,8 +7399,9 @@ - Finalist - Cross Site Scripting + Finalist - /wp-content/plugins/finalist/vote.php id Parameter Reflected XSS + 98665 http://packetstormsecurity.com/files/123597/ XSS @@ -7379,10 +7410,12 @@ - Dexs PM System Cross Site Scripting + Dexs PM System 1.0.1 - Private Message subject Parameter Stored XSS + 98668 + 55296 28970 - http://packetstormsecurity.com/files/123634/ + http://www.securityfocus.com/bid/63021 XSS @@ -7423,4 +7456,16 @@ + + + Social Sharing Toolkit 2.2.1 - Setting Manipulation CSRF + + 98717 + 2013-2701 + 52951 + + CSRF + + +