From 7f6cd57e517fbadb3f164b8fe6167a0a9286dfa0 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sun, 13 Oct 2013 11:02:39 +0200 Subject: [PATCH] Update plugin_vulns.xml --- data/plugin_vulns.xml | 61 +++++++++++++++++++++++-------------------- 1 file changed, 32 insertions(+), 29 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index e031715c..ad0c044d 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -5,7 +5,7 @@ - Content Slide 1.4.2 - Cross Site Requst Forgery Vulnerability + Content Slide <=1.4.2 - Cross Site Requst Forgery Vulnerability 93871 2013-2708 @@ -152,7 +152,7 @@ - Thank You Counter Button - XSS + Thank You Counter Button <=1.8.2 - XSS 50977 @@ -163,7 +163,7 @@ - Bookings - XSS + Bookings <=1.8.2 - XSS 50975 @@ -174,12 +174,13 @@ - Cimy User Manager - Arbitrary File Disclosure + Cimy User Manager <=1.4.2 - Arbitrary File Disclosure 50834 http://ceriksen.com/2012/10/24/wordpress-cimy-user-manager-arbitrary-file-disclosure/ UNKNOWN + 1.4.4 @@ -207,15 +208,17 @@ - WP125 - Multiple XSS + WP125 <=1.4.4 - Multiple XSS 50976 XSS + 1.4.5 - WP125 - CSRF + WP125 <=1.4.9 - CSRF + 2013-2700 http://www.securityfocus.com/bid/58934 CSRF @@ -6250,7 +6253,7 @@ - Digg Digg CSRF + Digg Digg - CSRF http://wordpress.org/plugins/digg-digg/changelog/ 53120 @@ -6276,7 +6279,7 @@ - FunCaptcha CSRF + FunCaptcha - CSRF http://wordpress.org/extend/plugins/funcaptcha/changelog/ @@ -6287,7 +6290,7 @@ - xili-language XSS + xili-language - XSS http://wordpress.org/plugins/xili-language/changelog/ @@ -6298,7 +6301,7 @@ - Security issue which allowed any user to reset settings + wordpress-seo - Security issue which allowed any user to reset settings http://wordpress.org/plugins/wordpress-seo/changelog/ @@ -6309,7 +6312,7 @@ - CSRF in WordPress underConstruction plugin + Under Construction - CSRF http://wordpress.org/plugins/underconstruction/changelog/ 52881 @@ -6323,7 +6326,7 @@ - ADIF Log Search Widget XSS Arbitrary Vulnerability + ADIF Log Search Widget - XSS Arbitrary Vulnerability http://packetstormsecurity.com/files/121777/ 53599 @@ -6358,7 +6361,7 @@ - Remote File Inclusion Vulnerability + Export to text - Remote File Inclusion Vulnerability 51348 93715 @@ -6472,7 +6475,7 @@ - WP Maintenance Mode Setting Manipulation CSRF + WP Maintenance Mode - Setting Manipulation CSRF 94450 @@ -6493,7 +6496,7 @@ - Leaflet Maps Marker Tag Multiple Parameter SQL Injection + Leaflet Maps Marker - Tag Multiple Parameter SQL Injection 94388 @@ -6526,7 +6529,7 @@ - Dropdown Menu Widget Script Insertion CSRF + Dropdown Menu Widget - Script Insertion CSRF 94771 @@ -6536,7 +6539,7 @@ - BuddyPress Extended Friendship Request wp-admin/admin-ajax.php friendship_request_message Parameter XSS + <title>BuddyPress Extended Friendship Request - wp-admin/admin-ajax.php friendship_request_message Parameter XSS 94807 @@ -6548,7 +6551,7 @@ - wp-private-messages /wp-admin/profile.php msgid Parameter SQL Injection + wp-private-messages - /wp-admin/profile.php msgid Parameter SQL Injection 94702 @@ -6558,7 +6561,7 @@ - Stream Video Player - - Setting Manipulation CSRF + Stream Video Player - Setting Manipulation CSRF 94466 @@ -6568,7 +6571,7 @@ - Duplicator installer.cleanup.php package Parameter XSS + Duplicator - installer.cleanup.php package Parameter XSS 95627 2013-4625 @@ -6580,7 +6583,7 @@ - Citizen Space Script Insertion CSRF + Citizen Space - Script Insertion CSRF 95570 @@ -6591,7 +6594,7 @@ - Spicy Blogroll spicy-blogroll-ajax.php Multiple Parameter Remote File Inclusion + Spicy Blogroll - spicy-blogroll-ajax.php Multiple Parameter Remote File Inclusion 95557 26804 @@ -6602,7 +6605,7 @@ - Pie Register wp-login.php Multiple Parameter XSS + Pie Register - wp-login.php Multiple Parameter XSS 95160 @@ -6613,7 +6616,7 @@ - CSRF in admin/setting.php in Xhanch + Xhanch my Twitter - CSRF in admin/setting.php 96027 53133 @@ -6640,7 +6643,7 @@ - CSRF in HMS Testimonials 2.0.10 + HMS Testimonials 2.0.10 - CSRF http://wordpress.org/plugins/hms-testimonials/changelog/ 2013-4240 @@ -6655,7 +6658,7 @@ 2.0.11 - XSS in HMS Testimonials 2.0.10 + HMS Testimonials 2.0.10 - XSS http://wordpress.org/plugins/hms-testimonials/changelog/ 2013-4241 @@ -6718,7 +6721,7 @@ - platinum_seo_pack.php s Parameter Reflected XSS + platinum_seo_pack.php - s Parameter Reflected XSS 97263 @@ -6796,11 +6799,11 @@ Lazy SEO 1.1.9 - lazyseo.php File Upload Arbitrary Code Execution - http://packetstormsecurity.com/files/123349/ - http://xforce.iss.net/xforce/xfdb/87384 97662 2013-5961 28452 + http://packetstormsecurity.com/files/123349/ + http://xforce.iss.net/xforce/xfdb/87384 UPLOAD