From e3bc50a163154c36298c5878ca936bb05b73af2b Mon Sep 17 00:00:00 2001 From: erwanlr Date: Tue, 27 May 2014 14:55:42 +0200 Subject: [PATCH 1/4] Fixes #487 --- data/plugin_vulns.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 1651ce0b..a64f194c 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -10500,7 +10500,7 @@ 3.7.2 - Contact Form 7 3.5.3 - Crafted File Extension Upload Remote Code Execution + Contact Form 7 & Old WP Versions - Crafted File Extension Upload Remote Code Execution 102776 http://packetstormsecurity.com/files/125018/ From 47d8818028f0d6852304f7cab775bb29fa95420a Mon Sep 17 00:00:00 2001 From: Peter Date: Wed, 28 May 2014 11:18:58 +0200 Subject: [PATCH 2/4] Update vuln db --- data/plugin_vulns.xml | 67 +++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 67 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index a64f194c..d68c8534 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -12727,4 +12727,71 @@ + + + Cool Video Gallery 1.8 - admin/gallery-details.php Multiple Actions CSRF + + 107354 + + CSRF + 1.9 + + + Cool Video Gallery 1.8 - admin/gallery-manage.php Gallery Deletion CSRF + + 107355 + + CSRF + 1.9 + + + Cool Video Gallery 1.8 - admin/gallery-settings.php Gallery Settings Manipulation CSRF + + 107356 + + CSRF + 1.9 + + + Cool Video Gallery 1.8 - admin/gallery-sort.php Gallery Sort Order Manipulation CSRF + + 107357 + + CSRF + 1.9 + + + Cool Video Gallery 1.8 - admin/player-settings.php Player Settings Manipulation CSRF + + 107358 + + CSRF + 1.9 + + + Cool Video Gallery 1.8 - admin/plugin-uninstall.php Plugin Uninstallation CSRF + + 107359 + + CSRF + 1.9 + + + Cool Video Gallery 1.8 - admin/video-sitemap.php XML Video Sitemap Generation CSRF + + 107360 + + CSRF + 1.9 + + + Cool Video Gallery 1.8 - lib/core.php Multiple Actions CSRF + + 107361 + + CSRF + 1.9 + + + From 098b14884db49f6091b7044513c1a279eb5d8bb8 Mon Sep 17 00:00:00 2001 From: erwanlr Date: Thu, 29 May 2014 14:46:54 +0200 Subject: [PATCH 3/4] Fixes #491 - DZS Video Gallery Content Spoofing & XSS --- data/plugin_vulns.xml | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index d68c8534..e7d5f141 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -10637,6 +10637,13 @@ FPD + + DZS Video Gallery - Flash Files Content Spoofing & Cross-Site Scripting + + http://seclists.org/fulldisclosure/2014/May/157 + + MULTI + @@ -12306,7 +12313,7 @@ 1.0.4 - + WP Business intelligence lite <= 1.0.6 - Remote Code Execution Exploit @@ -12585,7 +12592,7 @@ 1.2 - + Photo-Gallery - UploadHandler.php File Upload CSRF From c4b146b36b6ccdd5952b51696a3d30e5153ab861 Mon Sep 17 00:00:00 2001 From: erwanlr Date: Thu, 29 May 2014 14:53:42 +0200 Subject: [PATCH 4/4] Fixes #489 - Adds bib2html CVE --- data/plugin_vulns.xml | 1 + 1 file changed, 1 insertion(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index e7d5f141..81fd4a8d 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -12715,6 +12715,7 @@ bib2html 0.9.3 - /OSBiB/create/index.php styleShortName Parameter XSS 107296 + 2014-3870 http://packetstormsecurity.com/files/126782/ http://www.securityfocus.com/bid/67589