From 54036d562bbf8c981bd0c88c1a4a4748694e4906 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Wed, 9 Oct 2013 15:15:20 +0200 Subject: [PATCH 1/4] Update plugin_vulns.xml --- data/plugin_vulns.xml | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 2034321e..bb02e1c8 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -482,9 +482,12 @@ http://packetstormsecurity.com/files/119221/ 51037 + 23856 + 87353 exploit/unix/webapp/wp_advanced_custom_fields_exec RFI + 3.5.2 @@ -1611,10 +1614,14 @@ - WP-Property 1.35.0 Arbitrary File Upload + WP Property <=1.35.0 - Arbitrary File Upload 18987 - + 23651 + 82656 + 49394 + http://packetstormsecurity.com/files/113274/ + UPLOAD From d0f357332a59b549c02253c8474a80ac5d8788b0 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Wed, 9 Oct 2013 15:36:40 +0200 Subject: [PATCH 2/4] Update plugin_vulns.xml --- data/plugin_vulns.xml | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index bb02e1c8..7ee3285e 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -4582,7 +4582,7 @@ - Events Manager - Multiple XSS Vulnerabilities + Events Manager 5.3.3 - Multiple XSS Vulnerabilities 51869 @@ -4590,7 +4590,7 @@ 5.3.4 - Events Manager - Multiple XSS Vulnerabilities + Events Manager 5.3.8 - Multiple XSS Vulnerabilities http://www.securityfocus.com/bid/60078 53478 @@ -4600,8 +4600,9 @@ 5.3.9 - Events Manager - Multiple Unspecified XSS Vulnerabilities + Events Manager 5.5.1 - Multiple Unspecified XSS Vulnerabilities + 98198 55182 XSS @@ -6739,8 +6740,11 @@ All in One SEO Pack <= 2.3.0 - XSS Vulnerability + 98023 + 2013-5988 http://archives.neohapsis.com/archives/bugtraq/2013-10/0006.html http://packetstormsecurity.com/files/123490/ + http://www.securityfocus.com/bid/62784 55133 2.3.0.1 From 7726b3ae32262dca34c7d1d2d726f516f3c000c5 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Wed, 9 Oct 2013 16:31:13 +0200 Subject: [PATCH 3/4] Update plugin_vulns.xml --- data/plugin_vulns.xml | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 7ee3285e..fc77a5b7 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -1690,6 +1690,7 @@ Track That Stat <= 1.0.8 Cross Site Scripting http://packetstormsecurity.com/files/112722/ + http://www.securityfocus.com/bid/53551 XSS @@ -3719,6 +3720,13 @@ SQLI + + VideoWhisper Video Presentation 3.17 - 'vw_upload.php' Arbitrary File Upload Vulnerability + + http://www.securityfocus.com/bid/53851 + + UPLOAD + @@ -6952,4 +6960,13 @@ + + + Email Newsletter 8.0 - 'option' Parameter Information Disclosure Vulnerability + + http://www.securityfocus.com/bid/53850 + + + + From eb2bc58a591a07f9b1ebc54b29ebd26e5b7df734 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Wed, 9 Oct 2013 17:05:09 +0200 Subject: [PATCH 4/4] Update plugin_vulns.xml --- data/plugin_vulns.xml | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index fc77a5b7..1033d647 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -5699,6 +5699,7 @@ Simply Poll Plugin 1.4.1 - Multiple Vulnerabilities 24850 + 91446 MULTI @@ -5709,6 +5710,7 @@ Occasions Plugin 1.0.4 - CSRF Vulnerability 24858 + 91490 CSRF @@ -6969,4 +6971,23 @@ + + + IndiaNIC FAQs Manager Plugin 1.0 - Multiple Vulnerabilities + + 24867 + 91625 + + MULTI + + + IndiaNIC FAQs Manager Plugin 1.0 - Blind SQL Injection + + 24868 + 91623 + + SQLI + + +