From 921596f6f81492e6a7c929a76e34bd9315b45a55 Mon Sep 17 00:00:00 2001 From: Peter Date: Thu, 31 Jul 2014 11:43:42 +0200 Subject: [PATCH] Added WP-e-Commerce Vulns. Fix #640 --- data/plugin_vulns.xml | 52 ++++++++++++++++++++++++++++++------------- 1 file changed, 36 insertions(+), 16 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 144a5a98..bf02f875 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -5579,22 +5579,6 @@ - - WP e-Commerce 3.8.6 - wpsc-cart_widget.php cart_messages Parameter XSS - - 74295 - 45513 - - XSS - 3.8.8 - - - WP e-Commerce <= 3.8.6 - SQL Injection Vulnerability - - 17832 - - SQLI - WP-e-Commerce 3.8.9.5 - Cross Site Scripting Vulnerability @@ -5634,6 +5618,42 @@ UPLOAD + + WP-e-Commerce 3.8.9 - purchase-log-list-table-class.php m Parameter XSS + + 88231 + http://www.securityfocus.com/bid/56499 + http://xforce.iss.net/xforce/xfdb/80048 + + XSS + 3.8.9.1 + + + WP-e-Commerce 3.8.9 - purchaselogs.class.php view_purchlogs_by_status Parameter SQL Injection + + 88232 + http://www.securityfocus.com/bid/56499 + http://xforce.iss.net/xforce/xfdb/80042 + + SQLI + 3.8.9.1 + + + WP e-Commerce 3.8.6 - wpsc-cart_widget.php cart_messages Parameter XSS + + 74295 + 45513 + + XSS + 3.8.8 + + + WP e-Commerce <= 3.8.6 - SQL Injection Vulnerability + + 17832 + + SQLI +