From 4f50fbdfe4520b53ba9109f3cd88ace17d9eea8b Mon Sep 17 00:00:00 2001 From: Peter Date: Thu, 31 Jul 2014 13:16:51 +0200 Subject: [PATCH] Added new CVE's. Fix #572 --- data/plugin_vulns.xml | 50 ++++++++++++++++++++++++++++++++++++++----- 1 file changed, 45 insertions(+), 5 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 190956f4..dd4f6f40 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -13466,6 +13466,9 @@ Cross RSS 1.7 - proxy.php rss Parameter Local File Inclusion 108502 + 2014-4941 + http://www.securityfocus.com/bid/68555 + http://codevigilant.com/disclosure/wp-plugin-cross-rss-local-file-inclusion/ LFI @@ -13726,7 +13729,7 @@ BannerMan 0.2.4 - XSS in wp-admin/options-general.php via bannerman_background parameter 108682 - 2014-4945 + 2014-4845 http://packetstormsecurity.com/files/127289/ XSS @@ -13738,7 +13741,7 @@ Random Banner 1.1.2.1 - random-banner/random-banner.php buffercode_RBanner_url_banner1 Parameter XSS 108627 - 2014-4947 + 2014-4847 http://packetstormsecurity.com/files/127292/ http://www.securityfocus.com/bid/68280 @@ -13751,7 +13754,7 @@ Blogstand Smart Banner 1.0 - blogstand-banner.php bs_blog_id Parameter XSS 108625 - 2014-4948 + 2014-4848 http://packetstormsecurity.com/files/127290/ http://www.securityfocus.com/bid/68282 @@ -13764,7 +13767,7 @@ Construction Mode 1.8 - under-construction.php wuc_logo Parameter XSS 108630 - 2014-4954 + 2014-4854 58932 http://packetstormsecurity.com/files/127287/ http://www.securityfocus.com/bid/68287 @@ -13778,7 +13781,7 @@ Polylang 1.5.1 - User Description Handling Stored XSS 108634 - 2014-4955 + 2014-4855 59357 http://www.securityfocus.com/bid/68509 @@ -13795,4 +13798,41 @@ + + + ENL Newsletter 1.0.1 - wp-admin/admin.php enl-add-new Page id Parameter SQL Injection + + 109027 + 2014-4939 + http://codevigilant.com/disclosure/wp-plugin-enl-newsletter-a1-injection/ + + SQLI + + + + + + Tera Charts 0.1 - charts/zoomabletreemap.php fn Parameter Remote Path Traversal File Disclosure + + 109029 + 2014-4940 + http://www.securityfocus.com/bid/68662 + http://codevigilant.com/disclosure/wp-plugin-tera-chart-local-file-inclusion/ + + FPD + 1.0 + + + Tera Charts 0.1 - charts/treemap.php fn Parameter Remote Path Traversal File Disclosure + + 109028 + 2014-4940 + http://www.securityfocus.com/bid/68662 + http://codevigilant.com/disclosure/wp-plugin-tera-chart-local-file-inclusion/ + + FPD + 1.0 + + +