diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index ad75c218..d06857ee 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -593,11 +593,12 @@ - SWF Vulnerable to XSS Bundled in Many WordPress Plugins + Comment Extra Field 1.7 - CSRF / XSS + http://packetstormsecurity.com/files/122625/ http://brindi.si/g/blog/vulnerable-swf-bundled-in-wordpress-plugins.html - XSS + MULTI @@ -3020,11 +3021,34 @@ MULTI - Mingle Forum 1.0.33.3 - Multiple Parameter SQL Injection + Mingle Forum 1.0.33.3 - fs-admin.php togroupusers Parameter XSS + + 90432 + 2013-0734 + 52167 + + XSS + 1.0.34 + + + Mingle Forum 1.0.33.3 - wpf.class.php search_words Parameter XSS + + 90433 + 2013-0734 + 52167 + + XSS + 1.0.34 + + + Mingle Forum 1.0.33.3 - wpf.class.php Multiple Parameter SQL Injection 90434 + 2013-0735 + 52167 SQLI + 1.0.34 Mingle Forum 1.0.35 - Privilege Escalation CSRF @@ -5860,8 +5884,10 @@ - Terillion Reviews - Cross Site Scripting + Terillion Reviews - Profile Id Field XSS + 91123 + 2013-1201 http://packetstormsecurity.com/files/120730/ XSS @@ -6679,6 +6705,7 @@ Xorbin Digital Flash Clock 1.0 - Flash-based XSS + http://packetstormsecurity.com/files/122223/ http://advisory.prakharprasad.com/xorbin_dfc_wp.txt 2013-4693 @@ -6756,6 +6783,7 @@ 95557 26804 + http://packetstormsecurity.com/files/122396/ RFI @@ -7080,7 +7108,7 @@ - LBG Zoominoutslider - XSS Vulnerability + LBG Zoominoutslider - add_banner.php name Parameter Stored XSS 97887 54983 @@ -7088,6 +7116,30 @@ XSS + + LBG Zoominoutslider - settings_form.php Multiple Parameter Stored XSS + + 99339 + http://seclists.org/fulldisclosure/2013/Nov/30 + + XSS + + + LBG Zoominoutslider - add_playlist_record.php Multiple Parameter Stored XSS + + 99340 + http://seclists.org/fulldisclosure/2013/Nov/30 + + XSS + + + LBG Zoominoutslider - Multiple Script Direct Request Path Disclosure + + 99341 + http://seclists.org/fulldisclosure/2013/Nov/30 + + FPD + @@ -7206,8 +7258,10 @@ Booking Calendar 4.1.4 - CSRF Vulnerability - 27399 96088 + 27399 + 54461 + http://packetstormsecurity.com/files/122691/ http://wpbookingcalendar.com/ CSRF @@ -7233,10 +7287,12 @@ 98279 28808 + 55172 http://packetstormsecurity.com/files/123549/ http://quick-plugins.com/quick-contact-form/ XSS + 6.1 @@ -7569,6 +7625,7 @@ Feed - news_dt.php nid Parameter SQL Injection 94804 + http://packetstormsecurity.com/files/122260/ SQLI @@ -7725,6 +7782,7 @@ 98831 2013-6281 55396 + http://packetstormsecurity.com/files/123699/ http://www.securityfocus.com/bid/63256 XSS @@ -7820,5 +7878,18 @@ + + + Facebook Survey Pro - timeline/index.php id Parameter SQL Injection + + 87817 + 22853 + http://packetstormsecurity.com/files/118238/ + http://www.securityfocus.com/bid/56595 + http://xforce.iss.net/xforce/xfdb/80141 + + SQLI + + diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index 4cf4030a..3b6e583d 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -1897,4 +1897,24 @@ + + + ThisWay - remote shell upload vulnerability + + http://packetstormsecurity.com/files/123895/ + + RCE + + + + + + Think Responsive 1.0 - Arbitrary shell upload vulnerability + + http://packetstormsecurity.com/files/123880/ + + RCE + + +