diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 81624571..60e871f6 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -1785,6 +1785,141 @@ MULTI + + FoxyPress 0.4.2.5 - documenthandler.php prefix Parameter SQL Injection + + 86804 + 22374 + http://xforce.iss.net/xforce/xfdb/79698 + + SQLI + + + FoxyPress 0.4.2.5 - foxypress-manage-emails.php id Parameter SQL Injection + + 86805 + 22374 + http://xforce.iss.net/xforce/xfdb/79697 + + SQLI + + + FoxyPress 0.4.2.5 - inventory-category.php Multiple Parameter SQL Injection + + 86806 + 22374 + http://xforce.iss.net/xforce/xfdb/79697 + + SQLI + + + FoxyPress 0.4.2.5 - reports.php Multiple Parameter XSS + + 86807 + 22374 + http://xforce.iss.net/xforce/xfdb/79699 + + XSS + + + FoxyPress 0.4.2.5 - foxypress-affiliate.php aff_id Parameter XSS + + 86808 + 22374 + http://xforce.iss.net/xforce/xfdb/79699 + + XSS + + + FoxyPress 0.4.2.5 - affiliate-management.php Multiple Parameter SQL Injection + + 86809 + 22374 + http://xforce.iss.net/xforce/xfdb/79697 + + SQLI + + + FoxyPress 0.4.2.5 - foxypress-manage-emails.php id Parameter XSS + + 86810 + 22374 + http://xforce.iss.net/xforce/xfdb/79699 + + XSS + + + FoxyPress 0.4.2.5 - order-management.php status Parameter XSS + + 86811 + 22374 + http://xforce.iss.net/xforce/xfdb/79699 + + XSS + + + FoxyPress 0.4.2.5 - affiliate-management.php page Parameter XSS + + 86812 + 22374 + http://xforce.iss.net/xforce/xfdb/79699 + + XSS + + + FoxyPress 0.4.2.5 - foxypress-affiliate.php url Parameter Arbitrary Site Redirect + + 86813 + 22374 + http://xforce.iss.net/xforce/xfdb/79700 + + UNKNOWN + + + FoxyPress 0.4.2.5 - Multiple CSV File Direct Request Information Disclosure + + 86814 + 22374 + http://xforce.iss.net/xforce/xfdb/79701 + + UNKNOWN + + + FoxyPress 0.4.2.5 - ajax.php Access Restriction Multiple Command Execution + + 86815 + 22374 + http://xforce.iss.net/xforce/xfdb/79703 + + RCE + + + FoxyPress 0.4.2.5 - Multiple Script Direct Request Path Disclosure + + 86816 + 22374 + http://xforce.iss.net/xforce/xfdb/79704 + + FPD + + + FoxyPress 0.4.2.5 - Multiple Object Deletion CSRF + + 86817 + 22374 + http://xforce.iss.net/xforce/xfdb/79702 + + CSRF + + + FoxyPress 0.4.2.5 - documenthandler.php File Upload Arbitrary Code Execution + + 86818 + 22374 + http://xforce.iss.net/xforce/xfdb/79697 + + RCE +