diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 122b1269..f75198f3 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -6063,10 +6063,20 @@ + + WooCommerce SagePay Direct Payment Gateway 0.1.6.6 - pages/3DRedirect.php Multiple Parameter Reflected XSS + + 102882 + 56801 + + XSS + 0.1.6.7 + WooCommerce SagePay Direct Payment Gateway 0.1.6.6 - pages/3DCallBack.php Multiple Parameter Reflected XSS 102746 + 56801 XSS 0.1.6.7 @@ -6075,6 +6085,7 @@ WooCommerce SagePay Direct Payment Gateway 0.1.6.6 - pages/3DComplete.php Multiple Parameter Reflected XSS 102747 + 56801 XSS 0.1.6.7 @@ -10791,4 +10802,15 @@ + + + Delightful Downloads 1.3.1.1 - meta-boxes.php dedo_meta_boxes_save Function Multiple Action Authorization Bypass + + 102932 + + AUTHBYPASS + 1.3.2 + + + diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index 0daf7866..b486b0fc 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -2900,6 +2900,14 @@ + + InFocus - prettyPhoto Cross-Site Scripting Vulnerability + + 56583 + http://packetstormsecurity.com/files/124960/ + + XSS + InFocus 3.3 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion @@ -2908,7 +2916,7 @@ http://www.securityfocus.com/bid/64501 UNKNOWN - 2.5 + 3.4 InFocus 3.3 - dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download @@ -2967,4 +2975,16 @@ + + + Dandelion - Arbitry File Upload + + 99043 + 31424 + http://packetstormsecurity.com/files/125098/ + + UPLOAD + + +