From 24e039c177f3aaa86987581ba4f98a021d239b83 Mon Sep 17 00:00:00 2001 From: cervoise Date: Thu, 13 Jun 2013 11:49:19 +0200 Subject: [PATCH] Update plugin_vulns.xml Add underconstruction, adif-log-search-widget, exploit-scanner, ga-universal, export-to-text, qtranslate, catalog, uk-cookie (one vulnerability each). Add two vulnerabilities for nextgen-gallery. Add fixed_in for first nextgen-gallery vuln. Add fixed in for second nextgen-gallery vuln. --- data/plugin_vulns.xml | 74 +++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 74 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 4e1f47b2..4f8fa925 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -641,6 +641,11 @@ http://secunia.com/advisories/51143/ MULTI + + WordPress Spider Catalog Plugin Multiple SQL Injection and Cross Site Scripting Vulnerabilities + http://www.securityfocus.com/bid/60079/info + MULTI + @@ -2150,11 +2155,24 @@ http://brindi.si/g/blog/vulnerable-swf-bundled-in-wordpress-plugins.html http://secunia.com/advisories/51271/ XSS + 1.9.8 XSS in NextGEN Gallery <= 1.5.1 http://www.exploit-db.com/exploits/12098/ XSS + 1.5.2 + + + swfupload.swf Multiple Cross Site Scripting Vulnerabilities + http://www.securityfocus.com/bid/60433 + MULTI + + + NextGEN Gallery 1.9.12 Arbitrary File Upload (CVE-2013-3684) + http://wordpress.org/plugins/nextgen-gallery/changelog/ + UPLOAD + 1.9.13 @@ -4456,6 +4474,11 @@ http://seclists.org/bugtraq/2012/Nov/50 XSS + + WordPress plugin uk-cookie CSRF + http://www.openwall.com/lists/oss-security/2013/06/06/10 + CSRF + @@ -4617,5 +4640,56 @@ 1.4.5 + + + + CSRF in WordPress underConstruction plugin (CVE-2013-2699) + http://wordpress.org/plugins/underconstruction/changelog/ + CSRF + 1.09 + + + + + + ADIF Log Search Widget XSS Arbitrary Vulnerability + http://packetstorm.interhost.co.il/1305-exploits/adif-xss.txt + XSS + + + + + + FPD and Security bypass vulnerabilities in Exploit Scanner for WordPress + http://seclists.org/fulldisclosure/2013/May/216 + MULTI + + + + + + FPD and Security bypass vulnerabilities in Exploit Scanner for WordPress + http://wordpress.org/plugins/ga-universal/changelog/ + XSS + 1.0.1 + + + + + + Remote File Inclusion Vulnerability + http://secunia.com/advisories/51348/ + RFI + 2.3 + + + + + + WordPress qTranslate Plugin Cross-Site Request Forgery Vulnerability + http://secunia.com/advisories/53126/ + CSRF + +