diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index c05a0f6e..3cfb0165 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -1025,7 +1025,7 @@ - Catalog - HTML Code Injection and Cross-site scripting + Spider Catalog - HTML Code Injection and Cross-site scripting http://packetstormsecurity.com/files/117820/ 51143 @@ -1040,12 +1040,104 @@ MULTI - Spider Catalog 1.4.6 - Multiple Vulnerabilities + Spider Catalog 1.4.6 - Multiple Shortcode id Parameter SQL Injection + 93589 25724 - 93591 + 53491 + http://seclists.org/bugtraq/2013/May/79 - MULTI + SQL + + + Spider Catalog 1.4.6 - catalog.php catalog_after_search_results Function s Parameter SQL Injection + + 93590 + 25724 + 53491 + http://seclists.org/bugtraq/2013/May/79 + + SQL + + + Spider Catalog 1.4.6 - Categories.php Multiple Function id Parameter SQL Injection + + 93591 + 25724 + 53491 + http://seclists.org/bugtraq/2013/May/79 + + SQL + + + Spider Catalog 1.4.6 - products.php Multiple Function Multiple Parameter SQL Injection + + 93592 + 25724 + 53491 + http://seclists.org/bugtraq/2013/May/79 + + SQL + + + Spider Catalog 1.4.6 - Category Entry Multiple Field XSS + + 93593 + 25723 + 53491 + http://seclists.org/bugtraq/2013/May/79 + + XSS + + + Spider Catalog 1.4.6 - Categories.html.php Multiple Parameter XSS + + 93594 + 25724 + 53491 + http://seclists.org/bugtraq/2013/May/79 + + XSS + + + Spider Catalog 1.4.6 - Products.html.php Multiple Parameter XSS + + 93595 + 25724 + 53491 + http://seclists.org/bugtraq/2013/May/79 + + XSS + + + Spider Catalog 1.4.6 - spiderBox/spiderBox.js.php Multiple Parameter XSS + + 93596 + 25724 + 53491 + http://seclists.org/bugtraq/2013/May/79 + + XSS + + + Spider Catalog 1.4.6 - catalog.php spider_box_js_php Function Multiple Parameter XSS + + 93597 + 25724 + 53491 + http://seclists.org/bugtraq/2013/May/79 + + XSS + + + Spider Catalog 1.4.6 - Multiple Script Direct Request Path Disclosure + + 93598 + 25724 + 53491 + http://seclists.org/bugtraq/2013/May/79 + + FPD @@ -1665,9 +1757,12 @@ - Tinymce Thumbnail Gallery 1.0.7 - Remote File Disclosure + Tinymce Thumbnail Gallery 1.0.7 - download-image.php href Parameter Traversal Arbitrary File Access + 82706 + 49460 19022 + http://packetstormsecurity.org/files/113417/ UNKNOWN @@ -2039,6 +2134,14 @@ CSRF + + Sharebar 1.2.3 - wp-admin/options-general.php status Parameter XSS + + 81465 + 48908 + + XSS + Sharebar <= 1.2.1 - SQL Injection / Cross Site Scripting @@ -2399,12 +2502,30 @@ 2.4.8 - Zingiri Web Shop <= 2.4.0 - Multiple XSS Vulnerabilities + Zingiri Web Shop <= 2.4.0 - zing.inc.php page Parameter XSS + 81492 + 2012-6506 18787 48991 + http://www.securityfocus.com/bid/53278 + http://xforce.iss.net/xforce/xfdb/75178 XSS + 2.4.2 + + + Zingiri Web Shop <= 2.4.0 - onecheckout.php notes Parameter XSS + + 81493 + 2012-6506 + 18787 + 48991 + http://www.securityfocus.com/bid/53278 + http://xforce.iss.net/xforce/xfdb/75179 + + XSS + 2.4.2 Zingiri Web Shop <= 2.3.5 - Cross Site Scripting @@ -5742,8 +5863,10 @@ - WP ecommerce Shop Styling - "dompdf" Remote File Inclusion Vulnerability + WP ecommerce Shop Styling 1.7.2 - generate-pdf.php dompdf Parameter Remote File Inclusion + 89921 + 2013-0724 51707 RFI @@ -5753,8 +5876,9 @@ - Audio Player - XSS in SWF + Audio Player - player.swf playerID Parameter XSS + 89963 http://seclists.org/bugtraq/2013/Feb/35 52083 @@ -7751,7 +7875,7 @@ - A Forms 1.4.0 - Multiple Parameters SQL Injection + A Forms 1.4.0 - a-forms.php a_form_tracking_page FunctionMultiple Parameters SQL Injection 96404 @@ -7759,12 +7883,66 @@ 1.4.2 - A Forms 1.4.1 - Form Submission CSRF + A Forms 1.4.0 - Form Submission CSRF 96381 54489 CSRF + 1.4.1 + + + A Forms 1.4.0 - a-forms.php a_form_shortcode Function Multiple Parameter XSS + + 96410 + 54489 + + XSS + 1.4.2 + + + A Forms 1.4.0 - a-forms.php add_field_to_section Function Multiple Parameter XSS + + 96810 + 54489 + + XSS + 1.4.2 + + + A Forms 1.4.0 - a-forms.php a_form_initial_page Function Multiple Parameter XSS + + 96811 + 54489 + + XSS + 1.4.2 + + + A Forms 1.4.0 - a-forms.php a_form_page Function Multiple Parameter XSS + + 96812 + 54489 + + XSS + 1.4.2 + + + A Forms 1.4.0 - a-forms.php a_form_section_page Function message Parameter XSS + + 96813 + 54489 + + XSS + 1.4.2 + + + A Forms 1.4.0 - a-forms.php a_form_tracking_page Function Multiple Parameter XSS + + 96814 + 54489 + + XSS 1.4.2 @@ -8143,6 +8321,7 @@ 98978 XSS + 4.0.2 @@ -8453,4 +8632,56 @@ + + + Editorial Calendar 2.6 - Post Title XSS + + 90226 + + XSS + 2.7 + + + Editorial Calendar 2.6 - Permission Verification Arbitrary Calendar Post Deletion + + 90227 + 52218 + + AUTHBYPASS + 2.7 + + + Editorial Calendar 2.6 - Post Query Multiple Filter SQL Injection + + 90228 + + SQLI + + + + + + ShareYourCart 1.6.1 - SDK Multiple Unspecified Path Disclosure + + 81618 + 2012-4332 + 48960 + + UNKNOWN + 1.7.1 + + + + + + ALO EasyMail Newsletter 2.4.7 - Multiple Unspecified XSS + + 82324 + 49320 + + XSS + 2.4.8 + + +