From 864b892da099e149102266d4fe3edcac1113916d Mon Sep 17 00:00:00 2001 From: Peter Date: Mon, 27 Jan 2014 12:19:24 +0100 Subject: [PATCH] Update plugin_vulns.xml --- data/plugin_vulns.xml | 90 +++++++++++++++++++++++++++++++++++++++---- 1 file changed, 82 insertions(+), 8 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 5cb08f3d..9cec20e9 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -1267,13 +1267,21 @@ - Wordfence 3.3.5 - XSS and IAA + Wordfence 3.8.6 - lib/IPTraf.php User-Agent Header Stored XSS - http://seclists.org/fulldisclosure/2012/Oct/139 - 51055 + 102445 + 56558 - MULTI + XSS + 3.8.7 + + Wordfence 3.8.1 - lib/wordfenceClass.php isStrongPasswd Function Password Creation Restriction Bypass Weakness + + 102478 + + AUTHBYPASS + 3.8.3 Wordfence 3.8.1 - wp-admin/admin.php whois Parameter Stored XSS @@ -1284,6 +1292,17 @@ XSS 3.8.3 + + + Wordfence 3.3.5 - XSS and IAA + + 86557 + 51055 + http://seclists.org/fulldisclosure/2012/Oct/139 + + MULTI + 3.3.7 + @@ -4945,7 +4964,7 @@ WP-e-Commerce 3.8.9.5 - save-data.functions.php GIF File Upload - 102487 + 102497 http://packetstormsecurity.com/files/124921/ UPLOAD @@ -8883,11 +8902,29 @@ - Landing Pages - Unspecified SQL Injection + Landing Pages 1.2.3 - Unspecified Issue + + 102442 + + UNKNOWN + 1.3.1 + + + Landing Pages 1.2.1 - module.utils.php post Parameter SQL Injection 98334 + 2013-6243 55192 http://www.securityfocus.com/bid/62942 + http://xforce.iss.net/xforce/xfdb/87803 + + SQLI + 1.2.3 + + + Landing Pages 1.2.1 - module.redirect-ab-testing.php permalink_name Parameter SQL Injection + + 102407 SQLI 1.2.3 @@ -10263,8 +10300,34 @@ - SS Downloads 1.4.4.1 - Multiple Cross-Site Scripting Vulnerabilities + SS Downloads 1.4.4.1 - services/getfile.php file Parameter XSS + 102501 + + XSS + 1.5 + + + SS Downloads 1.4.4.1 - ss-downloads.php Multiple Variables XSS + + 102502 + + XSS + 1.5 + + + SS Downloads 1.4.4.1 - templates/download.php Multiple Parameters Reflected XSS + + 102503 + 56428 + + XSS + 1.5 + + + SS Downloads 1.4.4.1 - templates/register.php Multiple Parameter Reflected XSS + + 102504 56428 XSS @@ -10276,7 +10339,7 @@ Global Flash Galleries - swfupload.php Unauthenticated Image Upload Weakness - 102433 + 102423 http://www.securityfocus.com/bid/65060 UPLOAD @@ -10295,4 +10358,15 @@ + + + Let Them Unsubscribe 1.0 - let-them-unsubscribe.php Multiple Unspecified Issues + + 102500 + + MULTI + 1.1 + + +