Update plugin_vulns.xml
This commit is contained in:
@@ -7524,10 +7524,12 @@
|
|||||||
|
|
||||||
<plugin name="wp-realty">
|
<plugin name="wp-realty">
|
||||||
<vulnerability>
|
<vulnerability>
|
||||||
<title>wp-realty - MySQL Time Based Injection</title>
|
<title>WP Realty - MySQL Time Based Injection</title>
|
||||||
<references>
|
<references>
|
||||||
|
<osvdb>98748</osvdb>
|
||||||
<exploitdb>29021</exploitdb>
|
<exploitdb>29021</exploitdb>
|
||||||
<url>http://www.exploit-db.com/exploits/29021/</url>
|
<url>http://packetstormsecurity.com/files/123655/</url>
|
||||||
|
<url>http://www.securityfocus.com/bid/63217</url>
|
||||||
</references>
|
</references>
|
||||||
<type>SQLI</type>
|
<type>SQLI</type>
|
||||||
</vulnerability>
|
</vulnerability>
|
||||||
@@ -7601,11 +7603,22 @@
|
|||||||
|
|
||||||
<plugin name="blue-wrench-videos-widget">
|
<plugin name="blue-wrench-videos-widget">
|
||||||
<vulnerability>
|
<vulnerability>
|
||||||
<title>Blue Wrench Video-Widget CSRF and Persistent XSS 0day Disclosure</title>
|
<title>Blue Wrench Video Widget 1.0.2 - admin.php bw-videos Page Multiple Action CSRF</title>
|
||||||
<references>
|
<references>
|
||||||
|
<osvdb>98922</osvdb>
|
||||||
|
<secunia>55456</secunia>
|
||||||
<url>http://securityundefined.com/wordpress-plugin-blue-wrench-video-widget-csrf-persistent-xss-0day-disclosure/</url>
|
<url>http://securityundefined.com/wordpress-plugin-blue-wrench-video-widget-csrf-persistent-xss-0day-disclosure/</url>
|
||||||
</references>
|
</references>
|
||||||
<type>MULTI</type>
|
<type>CSRF</type>
|
||||||
|
</vulnerability>
|
||||||
|
<vulnerability>
|
||||||
|
<title>Blue-Wrench-Video-Widget 1.0.2 - admin.php bw-videos Page Multiple Parameter Stored XSS</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>98923</osvdb>
|
||||||
|
<secunia>55456</secunia>
|
||||||
|
<url>http://securityundefined.com/wordpress-plugin-blue-wrench-video-widget-csrf-persistent-xss-0day-disclosure/</url>
|
||||||
|
</references>
|
||||||
|
<type>XSS</type>
|
||||||
</vulnerability>
|
</vulnerability>
|
||||||
</plugin>
|
</plugin>
|
||||||
|
|
||||||
@@ -7641,4 +7654,27 @@
|
|||||||
</vulnerability>
|
</vulnerability>
|
||||||
</plugin>
|
</plugin>
|
||||||
|
|
||||||
|
<plugin name="payment-gateways-caller-for-wp-e-commerce">
|
||||||
|
<vulnerability>
|
||||||
|
<title>Payment Gateways Caller for WP e-Commerce 0.1.0 - load_merchant Parameter Traversal Local file Inclusion</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>98916</osvdb>
|
||||||
|
<url>http://packetstormsecurity.com/files/123744/</url>
|
||||||
|
</references>
|
||||||
|
<type>LFI</type>
|
||||||
|
<fixed_in>0.1.1</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
</plugin>
|
||||||
|
|
||||||
|
<plugin name="easy-photo-album">
|
||||||
|
<vulnerability>
|
||||||
|
<title>Easy Photo Album 1.1.5 - Album Information Disclosure</title>
|
||||||
|
<references>
|
||||||
|
<osvdb>98802</osvdb>
|
||||||
|
</references>
|
||||||
|
<type>AUTHBYPASS</type>
|
||||||
|
<fixed_in>1.1.6</fixed_in>
|
||||||
|
</vulnerability>
|
||||||
|
</plugin>
|
||||||
|
|
||||||
</vulnerabilities>
|
</vulnerabilities>
|
||||||
|
|||||||
Reference in New Issue
Block a user