From 16ba490f3f883bc1f32d08401927ab1dd2f073e4 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Tue, 5 Nov 2013 09:07:32 +0100 Subject: [PATCH 1/5] Added OSVDB #99339, #99340, #99341 --- data/plugin_vulns.xml | 27 +++++++++++++++++++++++++-- 1 file changed, 25 insertions(+), 2 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index ad75c218..0a5db73b 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -7080,7 +7080,7 @@ - LBG Zoominoutslider - XSS Vulnerability + LBG Zoominoutslider - add_banner.php name Parameter Stored XSS 97887 54983 @@ -7088,6 +7088,30 @@ XSS + + LBG Zoominoutslider - settings_form.php Multiple Parameter Stored XSS + + 99339 + http://seclists.org/fulldisclosure/2013/Nov/30 + + XSS + + + LBG Zoominoutslider - add_playlist_record.php Multiple Parameter Stored XSS + + 99340 + http://seclists.org/fulldisclosure/2013/Nov/30 + + XSS + + + LBG Zoominoutslider - Multiple Script Direct Request Path Disclosure + + 99341 + http://seclists.org/fulldisclosure/2013/Nov/30 + + FPD + @@ -7820,5 +7844,4 @@ - From 529660e622bc9fdcad1ae6292f0e61732c681e79 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Tue, 5 Nov 2013 09:32:08 +0100 Subject: [PATCH 2/5] Update theme_vulns.xml --- data/theme_vulns.xml | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index 4cf4030a..3b6e583d 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -1897,4 +1897,24 @@ + + + ThisWay - remote shell upload vulnerability + + http://packetstormsecurity.com/files/123895/ + + RCE + + + + + + Think Responsive 1.0 - Arbitrary shell upload vulnerability + + http://packetstormsecurity.com/files/123880/ + + RCE + + + From 99181a3bd98048e8c6d310b8336854ff14e3f0df Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Tue, 5 Nov 2013 09:52:33 +0100 Subject: [PATCH 3/5] Added OSVDB #90432, #90433, #90434 --- data/plugin_vulns.xml | 25 ++++++++++++++++++++++++- 1 file changed, 24 insertions(+), 1 deletion(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 0a5db73b..d6278bc5 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -3020,11 +3020,34 @@ MULTI - Mingle Forum 1.0.33.3 - Multiple Parameter SQL Injection + Mingle Forum 1.0.33.3 - fs-admin.php togroupusers Parameter XSS + + 90432 + 2013-0734 + 52167 + + XSS + 1.0.34 + + + Mingle Forum 1.0.33.3 - wpf.class.php search_words Parameter XSS + + 90433 + 2013-0734 + 52167 + + XSS + 1.0.34 + + + Mingle Forum 1.0.33.3 - wpf.class.php Multiple Parameter SQL Injection 90434 + 2013-0735 + 52167 SQLI + 1.0.34 Mingle Forum 1.0.35 - Privilege Escalation CSRF From 17fec7a16106fe605e958c419622e892c189b51e Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Tue, 5 Nov 2013 11:31:42 +0100 Subject: [PATCH 4/5] Update plugin_vulns.xml --- data/plugin_vulns.xml | 19 +++++++++++++++---- 1 file changed, 15 insertions(+), 4 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index d6278bc5..71114a2f 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -593,11 +593,12 @@ - SWF Vulnerable to XSS Bundled in Many WordPress Plugins + Comment Extra Field 1.7 - CSRF / XSS + http://packetstormsecurity.com/files/122625/ http://brindi.si/g/blog/vulnerable-swf-bundled-in-wordpress-plugins.html - XSS + MULTI @@ -5883,8 +5884,10 @@ - Terillion Reviews - Cross Site Scripting + Terillion Reviews - Profile Id Field XSS + 91123 + 2013-1201 http://packetstormsecurity.com/files/120730/ XSS @@ -6702,6 +6705,7 @@ Xorbin Digital Flash Clock 1.0 - Flash-based XSS + http://packetstormsecurity.com/files/122223/ http://advisory.prakharprasad.com/xorbin_dfc_wp.txt 2013-4693 @@ -6779,6 +6783,7 @@ 95557 26804 + http://packetstormsecurity.com/files/122396/ RFI @@ -7253,8 +7258,10 @@ Booking Calendar 4.1.4 - CSRF Vulnerability - 27399 96088 + 27399 + 54461 + http://packetstormsecurity.com/files/122691/ http://wpbookingcalendar.com/ CSRF @@ -7280,10 +7287,12 @@ 98279 28808 + 55172 http://packetstormsecurity.com/files/123549/ http://quick-plugins.com/quick-contact-form/ XSS + 6.1 @@ -7616,6 +7625,7 @@ Feed - news_dt.php nid Parameter SQL Injection 94804 + http://packetstormsecurity.com/files/122260/ SQLI @@ -7772,6 +7782,7 @@ 98831 2013-6281 55396 + http://packetstormsecurity.com/files/123699/ http://www.securityfocus.com/bid/63256 XSS From 71b821a653f4a5bae1b8b74d81b06250da7f24b0 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Tue, 5 Nov 2013 12:05:44 +0100 Subject: [PATCH 5/5] Added OSVDB #87817 --- data/plugin_vulns.xml | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 71114a2f..d06857ee 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -7878,4 +7878,18 @@ + + + Facebook Survey Pro - timeline/index.php id Parameter SQL Injection + + 87817 + 22853 + http://packetstormsecurity.com/files/118238/ + http://www.securityfocus.com/bid/56595 + http://xforce.iss.net/xforce/xfdb/80141 + + SQLI + + +