Some vulns added
This commit is contained in:
@@ -10,10 +10,51 @@
|
||||
<url>http://vagosec.org/2013/09/wordpress-php-object-injection/</url>
|
||||
<url>http://www.openwall.com/lists/oss-security/2013/09/12/1</url>
|
||||
<url>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4340</url>
|
||||
<cve>2013-4340</cve>
|
||||
<url>http://core.trac.wordpress.org/changeset/25325</url>
|
||||
<secunia>54803</secunia>
|
||||
<cve>2013-4338</cve>
|
||||
<osvdb>97211</osvdb>
|
||||
</references>
|
||||
<type>UNKNOWN</type>
|
||||
</vulnerability>
|
||||
<vulnerability>
|
||||
<title>wp-includes/functions.php get_allowed_mime_types Function SWF / EXE File Upload XSS Weakness</title>
|
||||
<references>
|
||||
<osvdb>97210</osvdb>
|
||||
<cve>2013-5739</cve>
|
||||
<url>http://core.trac.wordpress.org/changeset/25322</url>
|
||||
</references>
|
||||
<type>XSS</type>
|
||||
</vulnerability>
|
||||
<vulnerability>
|
||||
<title>Crafted String URL Redirect Restriction Bypass</title>
|
||||
<references>
|
||||
<osvdb>97212</osvdb>
|
||||
<cve>2013-4339</cve>
|
||||
<secunia>54803</secunia>
|
||||
<url>http://core.trac.wordpress.org/changeset/25323</url>
|
||||
</references>
|
||||
<type>UNKNOWN</type>
|
||||
</vulnerability>
|
||||
<vulnerability>
|
||||
<title>wp-admin/includes/post.php user_ID Parameter Manipulation Post Authorship Spoofing</title>
|
||||
<references>
|
||||
<osvdb>97213</osvdb>
|
||||
<cve>2013-4340</cve>
|
||||
<secunia>54803</secunia>
|
||||
<url>http://core.trac.wordpress.org/changeset/25321</url>
|
||||
</references>
|
||||
<type>UNKNOWN</type>
|
||||
</vulnerability>
|
||||
<vulnerability>
|
||||
<title>wp-includes/functions.php get_allowed_mime_types Function HTML File Upload XSS Weakness</title>
|
||||
<references>
|
||||
<osvdb>97214</osvdb>
|
||||
<cve>2013-5738</cve>
|
||||
<url>http://core.trac.wordpress.org/changeset/25322</url>
|
||||
</references>
|
||||
<type>XSS</type>
|
||||
</vulnerability>
|
||||
</wordpress>
|
||||
|
||||
<wordpress version="3.5.2">
|
||||
|
||||
Reference in New Issue
Block a user