diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 095a1ffd..215667cc 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -3101,6 +3101,62 @@ XSS 1.9.2 + + BuddyPress 1.7.1 - bp-activity-classes.php Multiple Parameter SQL Injection + + 104761 + + SQLI + 1.7.2 + + + BuddyPress 1.7.1 - bp-blogs-classes.php Multiple Parameter SQL Injection + + 104761 + + SQLI + 1.7.2 + + + BuddyPress 1.7.1 - bp-friends/bp-friends-classes.php Multiple Parameter SQL Injection + + 104760 + + SQLI + 1.7.2 + + + BuddyPress 1.7.1 - bp-core/bp-core-classes.php Multiple Parameter SQL Injection + + 104759 + + SQLI + 1.7.2 + + + BuddyPress 1.7.1 - bp-core/bp-core-functions.php page_ids Parameter SQL Injection + + 104758 + + SQLI + 1.7.2 + + + BuddyPress 1.7.1 - bp-core/bp-core-filters.php user_ids Parameter SQL Injection + + 104757 + + SQLI + 1.7.2 + + + BuddyPress 1.7.1 - bp-core/bp-core-cache.php object_ids Parameter SQL Injection + + 104755 + + SQLI + 1.7.2 + Buddypress - player.swf / jwplayer.swf playerready Parameter XSS @@ -3119,6 +3175,14 @@ SQLI 1.5.5 + + BuddyPress 1.2.9 - groups/test-group/activity/ activity_ids Parameter SQL Injection + + 104756 + + SQLI + 1.2.10 + @@ -11617,4 +11681,23 @@ + + + Analytics360 1.2.1 - analytics360.php Multiple Action CSRF + + 104743 + + CSRF + 1.2.2 + + + Analytics360 1.2 - analytics360.php a360_error Parameter Reflected XSS + + 104744 + + XSS + 1.2.1 + + +