From 93951197493d9a2fcaf32925105fc286e80e73ec Mon Sep 17 00:00:00 2001 From: Peter Date: Mon, 3 Feb 2014 13:55:18 +0100 Subject: [PATCH] Update vuln db --- data/plugin_vulns.xml | 15 +++++- data/wp_vulns.xml | 103 +++++++++++++++++++++++++++++++++++++++++- 2 files changed, 116 insertions(+), 2 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index ecb0c90b..c25b5894 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -208,9 +208,13 @@ - FireStorm Professional Real Estate - "id" SQL Injection Vulnerability + FireStorm Professional Real Estate 2.06.01 - xml/marker_listings.php id Parameter SQL Injection + 86686 51107 + 22071 + http://packetstormsecurity.com/files/118232/ + http://xforce.iss.net/xforce/xfdb/80261 SQLI 2.06.04 @@ -9745,6 +9749,15 @@ + + Contact Form 7 3.5.2 - Crafted File Extension Upload Remote Code Execution + + 102776 + http://seclists.org/fulldisclosure/2014/Feb/0 + + RCE + 3.5.3 + Contact Form 7 3.5.2 - File Upload Remote Code Execution diff --git a/data/wp_vulns.xml b/data/wp_vulns.xml index 9f535723..c9b705c5 100644 --- a/data/wp_vulns.xml +++ b/data/wp_vulns.xml @@ -3,7 +3,24 @@ + + + WordPress 3.3.1-3.8.1 - Media Manager Description Field Stored XSS + + 102763 + + XSS + + + + + WordPress 3.3.1-3.8.1 - Media Manager Description Field Stored XSS + + 102763 + + XSS + wp-admin/options-writing.php Cleartext Admin Credentials Disclosure @@ -15,6 +32,13 @@ + + WordPress 3.3.1-3.8.1 - Media Manager Description Field Stored XSS + + 102763 + + XSS + wp-admin/options-writing.php Cleartext Admin Credentials Disclosure @@ -26,6 +50,13 @@ + + WordPress 3.3.1-3.8.1 - Media Manager Description Field Stored XSS + + 102763 + + XSS + PHP Object Injection @@ -113,6 +144,13 @@ + + WordPress 3.3.1-3.8.1 - Media Manager Description Field Stored XSS + + 102763 + + XSS + Media Library Multiple Function Path Disclosure @@ -132,6 +170,13 @@ + + WordPress 3.3.1-3.8.1 - Media Manager Description Field Stored XSS + + 102763 + + XSS + Wordpress 3.4 - 3.5.1 /wp-admin/users.php Malformed s Parameter Path Disclosure @@ -205,6 +250,13 @@ + + WordPress 3.3.1-3.8.1 - Media Manager Description Field Stored XSS + + 102763 + + XSS + Wordpress 3.4 - 3.5.1 /wp-admin/users.php Malformed s Parameter Path Disclosure @@ -248,6 +300,13 @@ + + WordPress 3.3.1-3.8.1 - Media Manager Description Field Stored XSS + + 102763 + + XSS + Wordpress 3.4 - 3.5.1 /wp-admin/users.php Malformed s Parameter Path Disclosure @@ -298,6 +357,13 @@ + + WordPress 3.3.1-3.8.1 - Media Manager Description Field Stored XSS + + 102763 + + XSS + Wordpress 3.4 - 3.5.1 /wp-admin/users.php Malformed s Parameter Path Disclosure @@ -341,6 +407,13 @@ + + WordPress 3.3.1-3.8.1 - Media Manager Description Field Stored XSS + + 102763 + + XSS + Wordpress 3.4 - 3.5.1 /wp-admin/users.php Malformed s Parameter Path Disclosure @@ -384,6 +457,13 @@ + + WordPress 3.3.1-3.8.1 - Media Manager Description Field Stored XSS + + 102763 + + XSS + WordPress 3.3.2 - 3.5 Cross-Site Scripting (XSS) (Issue 3) @@ -415,6 +495,13 @@ + + WordPress 3.3.1-3.8.1 - Media Manager Description Field Stored XSS + + 102763 + + XSS + WordPress 3.3.2 - 3.5 Cross-Site Scripting (XSS) (Issue 3) @@ -439,6 +526,13 @@ + + WordPress 3.3.1-3.8.1 - Media Manager Description Field Stored XSS + + 102763 + + XSS + WordPress 3.3.2 - 3.5 Cross-Site Scripting (XSS) (Issue 3) @@ -477,6 +571,13 @@ + + WordPress 3.3.1-3.8.1 - Media Manager Description Field Stored XSS + + 102763 + + XSS + Multiple vulnerabilities including XSS and Privilege Escalation @@ -485,7 +586,7 @@ MULTI - Wordpress 3.3.1 Multiple CSRF Vulnerabilities + Wordpress 3.3.1 - Multiple CSRF Vulnerabilities 18791