From 59ef0b05a18bbe671cf37006168f190cc99de7b7 Mon Sep 17 00:00:00 2001 From: Peter Date: Mon, 30 Dec 2013 00:10:08 +0100 Subject: [PATCH] Update plugin_vulns.xml --- data/plugin_vulns.xml | 104 ++++++++++++++++++++++++++++++++++++++++-- 1 file changed, 99 insertions(+), 5 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index d1f594ab..1518645a 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -1366,11 +1366,13 @@ - ThreeWP Email Reflector 1.13 - Stored XSS + ThreeWP Email Reflector 1.13 - Subject Field XSS + 85134 20365 XSS + 1.16 @@ -4765,18 +4767,23 @@ - Mini Mail Dashboard Widget 1.36 - Remote File Inclusion + Mini Mail Dashboard Widget 1.36 - wp-mini-mail.php abspath Parameter Remote File Inclusion + 75402 17868 + RFI + 1.37 - Mini Mail Dashboard Widget 1.42 - Stored XSS + Mini Mail Dashboard Widget 1.42 - Message Body XSS + 85135 20358 XSS + 1.43 @@ -5500,11 +5507,32 @@ - Knews - Multilingual Newsletters Cross-Site Request Forgery Vulnerability + Knews 1.2.5 - Multilingual Newsletters Cross-Site Request Forgery Vulnerability + 88427 51543 + http://www.securityfocus.com/bid/56926 + http://xforce.iss.net/xforce/xfdb/80661 CSRF + 1.2.6 + + + Knews 1.2.5 - Unspecified XSS + + 88426 + + XSS + 1.2.6 + + + Knews 1.1.0 - wysiwyg/fontpicker/index.php ff Parameter XSS + + 83643 + 49825 + + XSS + 1.1.1 @@ -5906,8 +5934,18 @@ - Backend Localization - Cross-Site Scripting Vulnerabilities + Backend Localization 1.6.1 - options-general.php kau-boys_backend_localization_language Parameter XSS + 84418 + 50099 + + XSS + 2.0 + + + Backend Localization 1.6.1 - wp-login.php kau-boys_backend_localization_language Parameter XSS + + 84419 50099 XSS @@ -9267,4 +9305,60 @@ + + + Custom Tables 3.4.4 - iframe.php key Parameter XSS + + 83646 + 49823 + + XSS + + + + + + WP Socializer 2.4.2 - admin/wpsr-services-selector.php val Parameter XSS + + 83645 + 49824 + + XSS + + + + + + church_admin 0.33.4.5 - includes/validate.php id Parameter XSS + + 83644 + 49827 + + XSS + + + + + + PHPFreeChat 0.2.8 - lib/csstidy-1.2/css_optimiser.php url Parameter XSS + + 83642 + 49826 + + XSS + + + + + + Artiss Code Embed 2.0.1 - wp-admin/admin.php suffix Parameter XSS + + 83686 + 49848 + + XSS + 2.0.2 + + +