Update plugin_vulns.xml

This commit is contained in:
Peter van der Laan
2013-11-12 16:31:36 +01:00
parent f833181d81
commit 4e06939463

View File

@@ -493,7 +493,14 @@
</references>
<type>UPLOAD</type>
</vulnerability>
</plugin>
<vulnerability>
<title>Uploader 1.0.4 - notify.php blog Parameter XSS</title>
<references>
<osvdb>90840</osvdb>
<secunia>52465</secunia>
</references>
<type>XSS</type>
</vulnerability>
<plugin name="xerte-online">
<vulnerability>
@@ -2447,6 +2454,22 @@
</references>
<type>XSS</type>
</vulnerability>
<vulnerability>
<title>Count Per Day 3.2.3 - notes.php Malformed Requests Remote DoS</title>
<references>
<osvdb>90833</osvdb>
<url>http://seclists.org/fulldisclosure/2013/Mar/43</url>
</references>
<type>UNKNOWN</type>
</vulnerability>
<vulnerability>
<title>Count Per Day 3.2.3 - Multiple Script Direct Request Path Disclosure</title>
<references>
<osvdb>90832</osvdb>
<url>http://seclists.org/fulldisclosure/2013/Mar/43</url>
</references>
<type>FPD</type>
</vulnerability>
<vulnerability>
<title>Count Per Day 3.2.3 - Cross Site Scripting</title>
<references>
@@ -4832,6 +4855,33 @@
<type>XSS</type>
<fixed_in>5.3.4</fixed_in>
</vulnerability>
<vulnerability>
<title>Events Manager 5.3.5 - wp-admin/admin-ajax.php dbem_phone Parameter XSS</title>
<references>
<osvdb>90913</osvdb>
<secunia>52475</secunia>
</references>
<type>XSS</type>
<fixed_in>5.3.6</fixed_in>
</vulnerability>
<vulnerability>
<title>Events Manager 5.3.5 - index.php event_owner_name Parameter XSS</title>
<references>
<osvdb>90914</osvdb>
<secunia>52475</secunia>
</references>
<type>XSS</type>
<fixed_in>5.3.6</fixed_in>
</vulnerability>
<vulnerability>
<title>Events Manager 5.3.5 - wp-admin/post.php Multiple Parameter XSS</title>
<references>
<osvdb>90915</osvdb>
<secunia>52475</secunia>
</references>
<type>XSS</type>
<fixed_in>5.3.6</fixed_in>
</vulnerability>
<vulnerability>
<title>Events Manager 5.3.8 - Multiple XSS Vulnerabilities</title>
<references>
@@ -5555,9 +5605,19 @@
<plugin name="contact-form-plugin">
<vulnerability>
<title>Contact Form - XSS</title>
<title>Contact Form 3.34 - contact_form.php cntctfrm_contact_message Parameter XSS</title>
<references>
<osvdb>90502</osvdb>
<secunia>52179</secunia>
</references>
<type>XSS</type>
<fixed_in>3.35</fixed_in>
</vulnerability>
<vulnerability>
<title>Contact Form 3.36 - contact_form.php cntctfrm_contact_email Parameter XSS</title>
<references>
<osvdb>90503</osvdb>
<secunia>52250</secunia>
</references>
<type>XSS</type>
</vulnerability>
@@ -5608,9 +5668,11 @@
<plugin name="responsive-logo-slideshow">
<vulnerability>
<title>Responsive Logo Slideshow - Cross Site Scripting</title>
<title>Responsive Logo Slideshow - URL and Image Field XSS</title>
<references>
<osvdb>90406</osvdb>
<url>http://packetstormsecurity.com/files/120379/</url>
<url>http://seclists.org/bugtraq/2013/Feb/84</url>
</references>
<type>XSS</type>
</vulnerability>
@@ -6420,8 +6482,11 @@
<plugin name="feedweb">
<vulnerability>
<title>Feedweb - 'wp_post_id' Parameter XSS</title>
<title>Feedweb 1.8.8 - widget_remove.php wp_post_id Parameter XSS</title>
<references>
<osvdb>91951</osvdb>
<cve>2013-3720</cve>
<secunia>52855</secunia>
<url>http://www.securityfocus.com/bid/58771</url>
</references>
<type>XSS</type>
@@ -6502,9 +6567,10 @@
<plugin name="xili-language">
<vulnerability>
<title>xili-language - XSS</title>
<title>xili-language - index.php lang Parameter XSS</title>
<references>
<url>http://wordpress.org/plugins/xili-language/changelog/</url>
<osvdb>93233</osvdb>
<secunia>53364</secunia>
</references>
<type>XSS</type>
<fixed_in>2.8.6</fixed_in>
@@ -6528,6 +6594,14 @@
</references>
<type>XSS</type>
</vulnerability>
<vulnerability>
<title>WordPress SEO 1.4.6 - Reset Settings Feature Access Restriction Bypass</title>
<references>
<osvdb>92147</osvdb>
<secunia>52949</secunia>
</references>
<type>UNKNOWN>
</vulnerability>
</plugin>
<plugin name="underconstruction">