Some vulns added

This commit is contained in:
erwanlr
2013-09-17 14:34:33 +01:00
parent 4a4df8e1c4
commit 95557ce095
2 changed files with 90 additions and 1 deletions

View File

@@ -10,10 +10,51 @@
<url>http://vagosec.org/2013/09/wordpress-php-object-injection/</url>
<url>http://www.openwall.com/lists/oss-security/2013/09/12/1</url>
<url>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4340</url>
<cve>2013-4340</cve>
<url>http://core.trac.wordpress.org/changeset/25325</url>
<secunia>54803</secunia>
<cve>2013-4338</cve>
<osvdb>97211</osvdb>
</references>
<type>UNKNOWN</type>
</vulnerability>
<vulnerability>
<title>wp-includes/functions.php get_allowed_mime_types Function SWF / EXE File Upload XSS Weakness</title>
<references>
<osvdb>97210</osvdb>
<cve>2013-5739</cve>
<url>http://core.trac.wordpress.org/changeset/25322</url>
</references>
<type>XSS</type>
</vulnerability>
<vulnerability>
<title>Crafted String URL Redirect Restriction Bypass</title>
<references>
<osvdb>97212</osvdb>
<cve>2013-4339</cve>
<secunia>54803</secunia>
<url>http://core.trac.wordpress.org/changeset/25323</url>
</references>
<type>UNKNOWN</type>
</vulnerability>
<vulnerability>
<title>wp-admin/includes/post.php user_ID Parameter Manipulation Post Authorship Spoofing</title>
<references>
<osvdb>97213</osvdb>
<cve>2013-4340</cve>
<secunia>54803</secunia>
<url>http://core.trac.wordpress.org/changeset/25321</url>
</references>
<type>UNKNOWN</type>
</vulnerability>
<vulnerability>
<title>wp-includes/functions.php get_allowed_mime_types Function HTML File Upload XSS Weakness</title>
<references>
<osvdb>97214</osvdb>
<cve>2013-5738</cve>
<url>http://core.trac.wordpress.org/changeset/25322</url>
</references>
<type>XSS</type>
</vulnerability>
</wordpress>
<wordpress version="3.5.2">