diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 3e8f368c..662b6f5d 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -3040,6 +3040,14 @@ + + Zingiri Tickets 2.1.2 - Unspecified Issue + + 105015 + + UNKNOWN + 2.1.3 + Zingiri Tickets - File Disclosure @@ -5322,20 +5330,34 @@ - WP-Filebase Download Manager <= 0.2.9 - SQL Injection Vulnerability + WP-Filebase Download Manager 0.3.0.02 - class/Admin.php GetFileHash Function Remote Command Execution - 17808 + 105039 + 57456 + http://www.securityfocus.com/bid/66341 SQLI + 0.3.0.03 - WP-Filebase - Unspecified Vulnerabilities + WP-Filebase 0.2.9.24- Unspecified Vulnerabilities + 87294 51269 + http://xforce.iss.net/xforce/xfdb/80034 UNKNOWN 0.2.9.25 + + WP-Filebase Download Manager <= 0.2.9 - wpfb-ajax.php base Parameter SQL Injection + + 75308 + 45931 + 17808 + + SQLI + @@ -5784,15 +5806,30 @@ - XSS, CSRF and blind SQL injection in GD Star Rating 1.9.22 + GD Star Rating 1.9.22 - gd-star-rating-stats.php s Parameter SQL Injection + 105085 + http://packetstormsecurity.com/files/125932/ + http://seclists.org/fulldisclosure/2014/Mar/399 https://security.dxw.com/advisories/xss-csrf-and-blind-sql-injection-in-gd-star-rating-1-9-22/ - MULTI + SQLI - GD Star Rating - Export Security Bypass Security Issue + GD Star Rating 1.9.22 - gd-star-rating-stats.php Setting Manipulation CSRF + 105086 + 57667 + http://packetstormsecurity.com/files/125932/ + http://seclists.org/fulldisclosure/2014/Mar/399 + https://security.dxw.com/advisories/xss-csrf-and-blind-sql-injection-in-gd-star-rating-1-9-22/ + + CSRF + + + GD Star Rating 1.9.18 - Export Security Bypass Security Issue + + 105086 49850 AUTHBYPASS @@ -5806,12 +5843,22 @@ XSS - GD Star Rating <= 1.9.10 - SQL Injection + GD Star Rating <= 1.9.10 - gd-star-rating/export.php de Parameter SQL Injection + 83466 17973 SQLI + + GD Star Rating 1.9.7 - gd-star-rating/widgets/widget_top.php wpfn Parameter XSS + + 71060 + 43403 + http://seclists.org/bugtraq/2011/Feb/219 + + XSS + @@ -11843,6 +11890,7 @@ WP HTML Sitemap 1.2 - wp-html-sitemap.html Sitemap Deletion CSRF 105084 + http://packetstormsecurity.com/files/125933/ http://seclists.org/fulldisclosure/2014/Mar/400 https://security.dxw.com/advisories/csrf-vulnerability-in-wp-html-sitemap-1-2/ @@ -11980,4 +12028,16 @@ + + + Ajax Pagination 1.1 - wp-admin/admin-ajax.php loop Parameter Local File Inclusion + + 105087 + http://packetstormsecurity.com/files/125929/ + http://seclists.org/fulldisclosure/2014/Mar/398 + + LFI + + +