From 6fe3bafd4d47219d777b8bd7efc2878fd72cd98e Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Mon, 14 Oct 2013 17:51:47 +0200 Subject: [PATCH 1/3] Added OSVDB #89441, #89443, #89455 --- data/plugin_vulns.xml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index a22ddffe..ec493de8 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -2607,6 +2607,7 @@ WP Symposium <= 12.12 - Multiple SQL Injection Vulnerabilities + 89455 50674 http://ceriksen.com/2013/02/18/wp-symposium-multiple-sql-injection/ @@ -4609,6 +4610,8 @@ Cardoza Wordpress poll - Cross-Site Request Forgery Vulnerability + 89443 + 2013-1401 51925 CSRF @@ -4649,6 +4652,8 @@ DVS Custom Notification - Cross-Site Request Forgery Vulnerability + 89441 + 2012-4921 51531 CSRF @@ -7205,6 +7210,8 @@ 98352 2013-5977 + 28959 + 55265 CSRF 1.5.1.15 @@ -7214,6 +7221,7 @@ 98353 2013-5978 + 28959 XSS 1.5.1.15 From c3f31e2aeed3cfb065ef5a14c7b0c826527760b2 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Mon, 14 Oct 2013 19:40:05 +0200 Subject: [PATCH 2/3] Update theme_vulns.xml --- data/theme_vulns.xml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index 65bdfc3b..7270face 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -1573,8 +1573,10 @@ - Wordpress theme pinboard 1.0.6 XSS + pinboard 1.0.6 - includes/theme-options.php tab Parameter XSS + 90070 + 2013-0286 52079 http://seclists.org/oss-sec/2013/q1/274 http://cxsecurity.com/issue/WLB-2013020062 From 587f6adaa1e0116f0d41e34e23c12594b61dffc5 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Mon, 14 Oct 2013 20:03:50 +0200 Subject: [PATCH 3/3] Update plugin_vulns.xml --- data/plugin_vulns.xml | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index ec493de8..e589e2bd 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -2111,6 +2111,8 @@ Login With Ajax - Cross-Site Request Forgery Vulnerability + 93031 + 2013-2707 52950 CSRF @@ -6078,10 +6080,11 @@ - easy-adsense-lite - CSRF + easy-adsense-lite 6.06 - CSRF - 52953 + 92910 2013-2702 + 52953 CSRF 6.10