Added Blue Wrench Video Widget vulnerability found by SecurityUndefined

This commit is contained in:
Peter van der Laan
2013-10-25 09:41:17 +02:00
parent be3937c361
commit 96b6e5db87

View File

@@ -6052,8 +6052,7 @@
<title>social-media-widget - malicious code</title>
<references>
<url>http://plugins.trac.wordpress.org/changeset?reponame=&amp;old=691839%40social-media-widget%2Ftrunk&amp;new=693941%40social-media-widget%2Ftrunk</url>
<url>http://slashdot.org/submission/2592777/top-wordpress-widget-sold-off-turned-into-seo-spambot
</url>
<url>http://slashdot.org/submission/2592777/top-wordpress-widget-sold-off-turned-into-seo-spambot</url>
</references>
<type>UNKNOWN</type>
<fixed_in>4.0.2</fixed_in>
@@ -7577,7 +7576,16 @@
</references>
<type>XSS</type>
</vulnerability>
</plugin>
<plugin name="blue-wrench-videos-widget">
<vulnerability>
<title>Blue Wrench Video-Widget CSRF and Persistent XSS 0day Disclosure</title>
<references>
<url>http://securityundefined.com/wordpress-plugin-blue-wrench-video-widget-csrf-persistent-xss-0day-disclosure/</url>
</references>
<type>MULTI</type>
</vulnerability>
</plugin>
<plugin name="wp-mailup">