From 4bd0999c2ea77d1ddcc42c1871399ac66ef21b62 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Thu, 24 Oct 2013 20:40:17 +0200 Subject: [PATCH] update wordpress vulns --- data/plugin_vulns.xml | 73 ++++++++++++++++++++++++++++++++++++++++--- 1 file changed, 69 insertions(+), 4 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 02ca62d9..78ae8849 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -2247,6 +2247,15 @@ XSS + + CMS Tree Page View 1.2.4 - Page Creation CSRF + + 91270 + 52581 + + CSRF + 1.2.5 + @@ -4881,8 +4890,9 @@ - Wysija Newsletters - SQL Injection Vulnerability + Wysija Newsletters 2.2 - SQL Injection Vulnerability + 89924 https://www.htbridge.com/advisory/HTB23140 http://packetstormsecurity.com/files/120089/ http://seclists.org/bugtraq/2013/Feb/29 @@ -5280,7 +5290,9 @@ Simple History - RSS Feed "rss_secret" Disclosure Weakness + 89640 51998 + http://www.securityfocus.com/bid/57628 UNKNOWN 1.0.8 @@ -5358,8 +5370,9 @@ - CommentLuv - Cross Site Scripting Vulnerability + CommentLuv 2.92.3 - Cross Site Scripting Vulnerability + 89925 https://www.htbridge.com/advisory/HTB23138 http://packetstormsecurity.com/files/120090/ http://seclists.org/bugtraq/2013/Feb/30 @@ -5855,13 +5868,24 @@ - Occasions 1.0.4 - CSRF Vulnerability + Occasions 1.0.4 - Manipulation CSRF + 91489 24858 - 91490 + 52651 + http://packetstormsecurity.com/files/120871/ CSRF + + Occasions 1.0.4 - occasions/occasions.php occ_content1 Parameter XSS + + 91490 + 24858 + http://packetstormsecurity.com/files/120871/ + + XSS + @@ -7559,6 +7583,47 @@ XSS + + Car Demon 1.0.1 - /wp-admin/post.php Multiple Parameter XSS + + 90366 + 51088 + + XSS + + + + + + + MailUp 1.3.2 - ajax.functions.php Ajax Function Call Handling XSS Weakness + + 91274 + 2013-0731 + 51917 + + XSS + 1.3.3 + + + + + + WP Online Store 1.3.1 - index.php slug Parameter Traversal Local File Inclusion + + 90243 + 50836 + + LFI + + + WP Online Store 1.3.1 - index.php Multiple Parameter Traversal Arbitrary File Access + + 90244 + 50836 + + UNKNOWN +