From 5f2edac86a61ed0471c45a0b65e117faea80f68f Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sat, 26 Oct 2013 22:00:43 +0200 Subject: [PATCH] Update plugin_vulns.xml --- data/plugin_vulns.xml | 22 +++++++++++++++++++--- 1 file changed, 19 insertions(+), 3 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 8c7268ed..fe63acd5 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -4688,19 +4688,23 @@ - Cardoza WordPress poll - Cross-Site Request Forgery Vulnerability + Cardoza WordPress poll 34.05 - Multiple External Function Remote Poll Manipulation 89443 2013-1401 51925 + http://seclists.org/bugtraq/2013/Jan/86 + http://packetstormsecurity.com/files/119736/ CSRF 34.06 - Cardoza WordPress poll - Multiple SQL injection vulnerabilities + Cardoza WordPress poll - CWPPoll.js Multiple Method pollid Parameter SQL Injection - 51942 + 89444 + 2013-1400 + http://packetstormsecurity.com/files/119736/ http://www.girlinthemiddle.net/2013/01/multiple-sql-injection-vulnerabilities.html http://seclists.org/bugtraq/2013/Jan/86 @@ -7677,4 +7681,16 @@ + + + Hungred Post Thumbnail - hpt_file_upload.php File Upload PHP Code Execution + + 82830 + http://packetstormsecurity.com/files/113402/ + http://www.securityfocus.com/bid/53898 + + RCE + + +