diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index ff3fc046..4aa964b6 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -493,7 +493,14 @@ UPLOAD - + + Uploader 1.0.4 - notify.php blog Parameter XSS + + 90840 + 52465 + + XSS + @@ -2447,6 +2454,22 @@ XSS + + Count Per Day 3.2.3 - notes.php Malformed Requests Remote DoS + + 90833 + http://seclists.org/fulldisclosure/2013/Mar/43 + + UNKNOWN + + + Count Per Day 3.2.3 - Multiple Script Direct Request Path Disclosure + + 90832 + http://seclists.org/fulldisclosure/2013/Mar/43 + + FPD + Count Per Day 3.2.3 - Cross Site Scripting @@ -4832,6 +4855,33 @@ XSS 5.3.4 + + Events Manager 5.3.5 - wp-admin/admin-ajax.php dbem_phone Parameter XSS + + 90913 + 52475 + + XSS + 5.3.6 + + + Events Manager 5.3.5 - index.php event_owner_name Parameter XSS + + 90914 + 52475 + + XSS + 5.3.6 + + + Events Manager 5.3.5 - wp-admin/post.php Multiple Parameter XSS + + 90915 + 52475 + + XSS + 5.3.6 + Events Manager 5.3.8 - Multiple XSS Vulnerabilities @@ -5555,9 +5605,19 @@ - Contact Form - XSS + Contact Form 3.34 - contact_form.php cntctfrm_contact_message Parameter XSS + + 90502 + 52179 + + XSS + 3.35 + + + Contact Form 3.36 - contact_form.php cntctfrm_contact_email Parameter XSS 90503 + 52250 XSS @@ -5608,9 +5668,11 @@ - Responsive Logo Slideshow - Cross Site Scripting + Responsive Logo Slideshow - URL and Image Field XSS + 90406 http://packetstormsecurity.com/files/120379/ + http://seclists.org/bugtraq/2013/Feb/84 XSS @@ -6420,8 +6482,11 @@ - Feedweb - 'wp_post_id' Parameter XSS + Feedweb 1.8.8 - widget_remove.php wp_post_id Parameter XSS + 91951 + 2013-3720 + 52855 http://www.securityfocus.com/bid/58771 XSS @@ -6502,9 +6567,10 @@ - xili-language - XSS + xili-language - index.php lang Parameter XSS - http://wordpress.org/plugins/xili-language/changelog/ + 93233 + 53364 XSS 2.8.6 @@ -6528,6 +6594,14 @@ XSS + + WordPress SEO 1.4.6 - Reset Settings Feature Access Restriction Bypass + + 92147 + 52949 + + UNKNOWN> +