diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 86f0a9e8..0ef3e902 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -2007,12 +2007,20 @@ + + WP Property <= 1.38.3.2 - Non-administrative User XMLI Remote Information Disclosure + + 102709 + + UNKNOWN + 1.38.4 + WP Property <= 1.35.0 - Arbitrary File Upload + 82656 18987 23651 - 82656 49394 http://packetstormsecurity.com/files/113274/ @@ -5974,6 +5982,25 @@ + + + WooCommerce SagePay Direct Payment Gateway 0.1.6.6 - pages/3DCallBack.php Multiple Parameter Reflected XSS + + 102746 + + XSS + 0.1.6.7 + + + WooCommerce SagePay Direct Payment Gateway 0.1.6.6 - pages/3DComplete.php Multiple Parameter Reflected XSS + + 102747 + + XSS + 0.1.6.7 + + + WooCommerce Predictive Search - index.php rs Parameter XSS @@ -9733,6 +9760,13 @@ + + Amerisale-Re - Remote Shell Upload + + http://packetstormsecurity.com/files/124992/ + + UPLOAD + Amerisale-Re - netriesdetail/upload.php edit Parameter Reflected XSS @@ -10553,4 +10587,27 @@ + + + WP Social Invitations <=1.4.4.2 - test.php Multiple Parameter Reflected XSS + + 102741 + 56711 + + XSS + 1.4.4.3 + + + + + + Infusionsoft Gravity Forms Add-on 1.5.6 - Unspecified XSS + + 102742 + + XSS + 1.5.7 + + + diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index 0df318c1..82b09d89 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -2043,8 +2043,10 @@ - Photocrati - XSS + Photocrati 4.7.3 - photocrati-gallery/ecomm-sizes.php prod_id Parameter Reflected XSS + 102717 + 56690 http://packetstormsecurity.com/files/124986/ XSS