From 997f4d35c2f4d2733e1a57e208cd49e9cabba935 Mon Sep 17 00:00:00 2001 From: Peter Date: Sat, 15 Feb 2014 22:00:02 +0100 Subject: [PATCH] Update vuln db --- data/plugin_vulns.xml | 19 +++++++++++++++++-- 1 file changed, 17 insertions(+), 2 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index c4aa3510..b71e02ac 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -2926,16 +2926,20 @@ - Buddypress <= 1.9.1 - Privilege Escalation + Buddypress <= 1.9.1 - Crafted bp_new_group_id Cookie Arbitrary Group Manipulation + 103308 + 2014-1889 http://packetstormsecurity.com/files/125213/ UNKNOWN 1.9.2 - Buddypress <= 1.9.1 - Cross Site Scripting + Buddypress <= 1.9.1 - groups/create/step/group-details/ Group Name Field Stored XSS + 103307 + 2014-1888 http://packetstormsecurity.com/files/125212/ XSS @@ -10883,4 +10887,15 @@ + + + all_in_one_carousel 1.2.20 - /tpl/add_carousel.php id Parameter Reflected XSS + + 103351 + http://seclists.org/bugtraq/2014/Feb/38 + + XSS + + +