diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 46c36dea..3f0f600b 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -162,8 +162,9 @@ - Bookings <= 1.8.2 - XSS + Bookings <= 1.8.2 - controlpanel.php error Parameter XSS + 86613 50975 XSS @@ -344,12 +345,70 @@ MULTI - RokBox <= 2.13 - XSS,DoS,Disclosure,Upload Vulnerabilities + RokBox <= 2.13 - thumb.php src Parameter Malformed Input Path Disclosure - 54801 + 88604 http://packetstormsecurity.com/files/118884/ + http://xforce.iss.net/xforce/xfdb/80732 + http://www.securityfocus.com/bid/56953 + http://seclists.org/fulldisclosure/2012/Dec/159 - MULTI + UNKNOWN + + + RokBox <= 2.13 - thumb.php src Parameter XSS + + 88605 + http://packetstormsecurity.com/files/118884/ + http://xforce.iss.net/xforce/xfdb/80731 + http://www.securityfocus.com/bid/56953 + http://seclists.org/fulldisclosure/2012/Dec/159 + + XSS + + + RokBox <= 2.13 - rokbox.php Direct Request Path Disclosure + + 88606 + http://packetstormsecurity.com/files/118884/ + http://www.securityfocus.com/bid/56953 + http://seclists.org/fulldisclosure/2012/Dec/159 + + UNKNOWN + + + RokBox <= 2.13 - error_log Direct Request Error Log Information Disclosure + + 88607 + http://packetstormsecurity.com/files/118884/ + http://xforce.iss.net/xforce/xfdb/80761 + http://www.securityfocus.com/bid/56953 + http://seclists.org/fulldisclosure/2012/Dec/159 + + UNKNOWN + + + RokBox <= 2.13 - jwplayer/jwplayer.swf abouttext Parameter XSS + + 88608 + http://packetstormsecurity.com/files/118884/ + http://xforce.iss.net/xforce/xfdb/80731 + http://www.securityfocus.com/bid/56953 + http://seclists.org/fulldisclosure/2012/Dec/159 + + XSS + + + RokBox <= 2.13 - thumb.php src Parameter Arbitrary File Upload + + 88609 + http://packetstormsecurity.com/files/118884/ + http://xforce.iss.net/xforce/xfdb/80733 + http://xforce.iss.net/xforce/xfdb/80739 + http://www.securityfocus.com/bid/56953 + http://seclists.org/fulldisclosure/2012/Dec/159 + + UPLOAD @@ -680,6 +739,13 @@ XSS + + PDW File Browser - upload.php Arbitrary File Upload Vulnerability + + http://www.securityfocus.com/bid/53895 + + UPLOAD + @@ -1201,14 +1267,24 @@ - BBPress - SQL Injection / Path Disclosure + BBPress - Multiple Script Malformed Input Path Disclosure + 86399 22396 - 86400 http://xforce.iss.net/xforce/xfdb/78244 http://packetstormsecurity.com/files/116123/ - MULTI + SQLI + + + BBPress - forum.php page Parameter SQL Injection + + 86400 + 22396 + http://xforce.iss.net/xforce/xfdb/78244 + http://packetstormsecurity.com/files/116123/ + + SQLI @@ -5133,9 +5209,11 @@ Developer Formatter - CSRF and XSS Vulnerability + 89475 + 24294 + 51912 http://illsecure.com/code/Wordpress-DevFormatter-CSRF-Vulnerability.txt http://1337day.com/exploit/20210 - 51912 MULTI