From 6dee0c7e4b08125bac190cec25c480e194fe567e Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Fri, 18 Oct 2013 17:56:50 +0200 Subject: [PATCH 1/5] Added OSVDB #98668 --- data/plugin_vulns.xml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index c03d717f..e2838b15 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -7411,4 +7411,17 @@ + + + Dexs PM System 1.0.1 - Private Message subject Parameter Stored XSS + + 98668 + 55296 + 28970 + http://www.securityfocus.com/bid/63021 + + XSS + + + From bf3795bced3b029bea63b2a89f2c5849e03d86a9 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sat, 19 Oct 2013 13:53:56 +0200 Subject: [PATCH 2/5] Update plugin_vulns.xml --- data/plugin_vulns.xml | 19 ++++--------------- 1 file changed, 4 insertions(+), 15 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index e2838b15..eb95f2f6 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -7378,10 +7378,12 @@ - Dexs PM System Cross Site Scripting + Dexs PM System 1.0.1 - Private Message subject Parameter Stored XSS + 98668 + 55296 28970 - http://packetstormsecurity.com/files/123634/ + http://www.securityfocus.com/bid/63021 XSS @@ -7411,17 +7413,4 @@ - - - Dexs PM System 1.0.1 - Private Message subject Parameter Stored XSS - - 98668 - 55296 - 28970 - http://www.securityfocus.com/bid/63021 - - XSS - - - From 49883bbc3a50da2119ed39cc1bf08bb8b7c5c0c2 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sat, 19 Oct 2013 21:27:24 +0200 Subject: [PATCH 3/5] Update plugin_vulns.xml --- data/plugin_vulns.xml | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index eb95f2f6..664ebbb4 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -7002,8 +7002,9 @@ - NOSpamPTI 2.1 - Blind SQL Injection + NOSpamPTI 2.1 - wp-comments-post.php comment_post_ID Parameter SQL Injection + 97528 28485 2013-5917 http://packetstormsecurity.com/files/123331/ @@ -7368,8 +7369,9 @@ - Finalist - Cross Site Scripting + Finalist - /wp-content/plugins/finalist/vote.php id Parameter Reflected XSS + 98665 http://packetstormsecurity.com/files/123597/ XSS From edf2ac481b736091cfc233859c1dfca5e2c7da5c Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sun, 20 Oct 2013 12:06:21 +0200 Subject: [PATCH 4/5] Update plugin_vulns.xml --- data/plugin_vulns.xml | 53 ++++++++++++++++++++++++++++++++++++++++++- 1 file changed, 52 insertions(+), 1 deletion(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 664ebbb4..c6ca89ce 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -870,6 +870,16 @@ + + + Image Resizer - Cross Site Scripting + + http://packetstormsecurity.com/files/123651/ + + XSS + + + wp-levoslideshow - Arbitrary File Upload Vulnerability @@ -4775,13 +4785,20 @@ - WooCommerce - index.php calc_shipping_state Parameter XSS + WooCommerce 2.0.12 - index.php calc_shipping_state Parameter XSS 95480 XSS 2.0.13 + + WooCommerce 2.0.17 - Cross Site Scripting + + http://packetstormsecurity.com/files/123684/ + + XSS + @@ -7114,6 +7131,18 @@ + + + Quick Paypal Payments 3.0 - Payment Sending Multiple Parameter XSS + + 98715 + 55292 + http://packetstormsecurity.com/files/123662/ + + XSS + + + Email Newsletter 8.0 - 'option' Parameter Information Disclosure Vulnerability @@ -7415,4 +7444,26 @@ + + + WP Realty - Blind SQL Injection + + http://packetstormsecurity.com/files/123655/ + + SQLI + + + + + + Social Sharing Toolkit 2.2.1 - Setting Manipulation CSRF + + 98717 + 2013-2701 + 52951 + + CSRF + + + From 88611ad3e8160a0eef6509c98f7115cf4f16af3f Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sun, 20 Oct 2013 12:16:49 +0200 Subject: [PATCH 5/5] Update plugin_vulns.xml --- data/plugin_vulns.xml | 10 ---------- 1 file changed, 10 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index c6ca89ce..8ee9ef4b 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -7444,16 +7444,6 @@ - - - WP Realty - Blind SQL Injection - - http://packetstormsecurity.com/files/123655/ - - SQLI - - - Social Sharing Toolkit 2.2.1 - Setting Manipulation CSRF