From 7d07b27d4f4d47ebb298c56170236e8840dcfb89 Mon Sep 17 00:00:00 2001 From: Peter Date: Sat, 14 Dec 2013 22:12:32 +0100 Subject: [PATCH] Update theme_vulns.xml --- data/theme_vulns.xml | 74 +++++++++++++++++++++++++++++++++++++++++++- 1 file changed, 73 insertions(+), 1 deletion(-) diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index 724ba66e..f7931dc4 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -1789,9 +1789,13 @@ - Clockstone - upload.php Arbitrary File Upload Vulnerability + Clockstone 1.2 - upload.php Arbitrary File Upload Vulnerability + 88622 51619 + http://www.exploit-db.com/exploits/23494 + http://www.securityfocus.com/bid/56988 + http://xforce.iss.net/xforce/xfdb/80725 UPLOAD @@ -2527,4 +2531,72 @@ + + + TwentyTen 1.1-1.5 - loop.php Multiple File Extension Upload Arbitrary Code Execution + + 88822 + + RCE + + + + + + Nest - gerador_galeria.php codigo Parameter SQL Injection + + 88298 + http://www.securityfocus.com/bid/56792 + http://xforce.iss.net/xforce/xfdb/80503 + + SQLI + + + + + + Toolbox 1.4 - flyer.php mls Parameter SQL Injection + + 88293 + http://www.securityfocus.com/bid/56745 + + SQLI + + + + + + Oberliga - team.php team Parameter SQL Injection + + 88454 + http://packetstormsecurity.org/files/118368/ + http://xforce.iss.net/xforce/xfdb/80273 + + SQLI + + + + + + CStar Design 2.0 - flashmoXML.php id Parameter SQL Injection + + 88291 + http://www.securityfocus.com/bid/56694 + + SQLI + + + + + + Malmonation - debate.php id Parameter SQL Injection + + 87866 + http://packetstormsecurity.org/files/118340/ + http://xforce.iss.net/xforce/xfdb/80252 + + SQLI + + +