From e5f3b4bf1dd3fdee359dbaa7729e4af33147f66c Mon Sep 17 00:00:00 2001 From: Peter Date: Fri, 11 Jul 2014 18:20:30 +0200 Subject: [PATCH 1/3] Added some missing Theme names --- data/theme_vulns.xml | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index f820ba74..b2c60035 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -5,7 +5,7 @@ - VideoJS Cross-Site Scripting Vulnerability + Crius - VideoJS Cross-Site Scripting Vulnerability 53427 http://seclists.org/fulldisclosure/2013/May/77 @@ -16,7 +16,7 @@ - VideoJS Cross-Site Scripting Vulnerability + Source - VideoJS Cross-Site Scripting Vulnerability 53457 http://seclists.org/fulldisclosure/2013/May/77 @@ -27,7 +27,7 @@ - VideoJS Cross-Site Scripting Vulnerability + I Love It - VideoJS Cross-Site Scripting Vulnerability 53548 http://seclists.org/fulldisclosure/2013/May/77 @@ -38,7 +38,7 @@ - VideoJS Cross-Site Scripting Vulnerability + Smart Start - VideoJS Cross-Site Scripting Vulnerability 53460 http://seclists.org/fulldisclosure/2013/May/77 @@ -49,7 +49,7 @@ - VideoJS Cross-Site Scripting Vulnerability + Covert Videopress - VideoJS Cross-Site Scripting Vulnerability 53494 http://seclists.org/fulldisclosure/2013/May/77 @@ -60,7 +60,7 @@ - VideoJS Cross-Site Scripting Vulnerability + Photolio - VideoJS Cross-Site Scripting Vulnerability http://seclists.org/fulldisclosure/2013/May/77 @@ -70,7 +70,7 @@ - onepagewebsite Full Path Disclosure vulnerability + onepagewebsite - Full Path Disclosure vulnerability http://1337day.com/exploit/20027 From 9e7d3462ab0ba804ef2d4c8cfe0baf0c92f0b81e Mon Sep 17 00:00:00 2001 From: Peter Date: Mon, 14 Jul 2014 07:28:32 +0200 Subject: [PATCH 2/3] Added CVE's. Update #567 --- data/plugin_vulns.xml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 695f5b47..719f6b8b 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -7399,6 +7399,8 @@ Audio Player - player.swf playerID Parameter XSS 89963 + 2013-1464 + http://packetstormsecurity.com/files/120129/ http://seclists.org/bugtraq/2013/Feb/35 52083 @@ -7461,9 +7463,10 @@ smart-flv - jwplayer.swf XSS + 90606 + 2013-1765 http://www.openwall.com/lists/oss-security/2013/02/24/7 http://packetstormsecurity.com/files/115100/ - 90606 XSS From 2d3c7e65d2689e06c1cfb721add224e93ff2095a Mon Sep 17 00:00:00 2001 From: Peter Date: Tue, 15 Jul 2014 00:03:10 +0200 Subject: [PATCH 3/3] Added CVE's. Update #567 --- data/plugin_vulns.xml | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 719f6b8b..c6796262 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -7848,11 +7848,13 @@ - Terillion Reviews - Profile Id Field XSS + Terillion Reviews < 1.2 - Profile Id Field XSS 91123 - 2013-1201 + 2013-2501 http://packetstormsecurity.com/files/120730/ + http://www.securityfocus.com/bid/58415 + http://xforce.iss.net/xforce/xfdb/82727 XSS @@ -9105,6 +9107,7 @@ platinum_seo_pack.php - s Parameter Reflected XSS 97263 + 2013-5918 1.3.8 XSS @@ -10155,6 +10158,7 @@ 91274 2013-0731 + 2013-2640 51917 XSS