diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index b3a91b51..8debb1f4 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -4547,6 +4547,10 @@ W3 Total Cache - Username and Hash Extract + 92742 + 92741 + 2012-6079 + 2012-6078 http://seclists.org/fulldisclosure/2012/Dec/242 https://github.com/FireFart/W3TotalCacheExploit auxiliary/gather/wp_w3_total_cache_hash_extract @@ -7712,4 +7716,72 @@ + + + Spreadsheet - /dhtmlxspreadsheet/codebase/spreadsheet.php page Parameter Reflected XSS + + 98831 + 2013-6281 + 55396 + http://www.securityfocus.com/bid/63256 + + XSS + + + + + + Tweet Blender 4.0.1 - Unspecified XSS + + 98978 + + XSS + + + + + + WordPress SB Uploader 3.9 - Arbitrary File Upload Vulnerability + + http://packetstormsecurity.com/files/119159/ + + UPLOAD + + + + + + Connections <= 0.7.1.5 - Unspecified Security Vulnerability + + 2011-5254 + http://www.securityfocus.com/bid/51204 + + XSS + 0.7.1.5 + + + + + + Gallery Bank 2.0.19 - Multiple Unspecified XSS + + 99045 + 55443 + http://www.securityfocus.com/bid/63382 + + XSS + 2.0.20 + + + Gallery Bank 2.0.19 - Multiple Unspecified Issues + + 99046 + 55443 + http://www.securityfocus.com/bid/63382 + + UNKNOWN + 2.0.20 + + + diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index 0ae6c0ce..53077e3c 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -1854,4 +1854,36 @@ + + + SimpleDark 1.2.10 - 's' Parameter Cross Site Scripting Vulnerability + + http://www.securityfocus.com/bid/46615 + + XSS + + + + + + GeoPlaces - File Upload Handling Remote Command Execution + + 98975 + http://packetstormsecurity.com/files/123773/ + + RCE + + + + + + Curvo - wp-content/themes/curvo/functions/upload-handler.php File Upload CSRF + + 99043 + http://packetstormsecurity.com/files/123799/ + + CSRF + + + diff --git a/data/wp_vulns.xml b/data/wp_vulns.xml index 32eed501..4d6bfe14 100644 --- a/data/wp_vulns.xml +++ b/data/wp_vulns.xml @@ -587,6 +587,7 @@ Wordpress <= 3.1.2 Clickjacking Vulnerability http://seclists.org/fulldisclosure/2011/Sep/219 + http://www.securityfocus.com/bid/49730 UNKNOWN