From a4dfb05d0c8ee17eeb294c6935a0b09b2d01c190 Mon Sep 17 00:00:00 2001 From: Peter Date: Tue, 8 Apr 2014 09:04:52 +0200 Subject: [PATCH] Update vuln db --- data/plugin_vulns.xml | 32 +++++++++++++++++++++++++++++--- data/theme_vulns.xml | 35 +++++++++++++++++++++++++++++++++++ 2 files changed, 64 insertions(+), 3 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index ca25eb06..577fbb76 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -10446,6 +10446,7 @@ JS MultiHotel 2.2.1 - includes/show_image.php file Parameter Remote File Inclusion DoS 105185 + http://packetstormsecurity.com/files/125959/ http://seclists.org/fulldisclosure/2014/Mar/428 RFI @@ -10454,6 +10455,7 @@ JS MultiHotel 2.2.1 - includes/delete_img.php path Parameter Reflected XSS 105186 + http://packetstormsecurity.com/files/125959/ http://seclists.org/fulldisclosure/2014/Mar/428 http://www.securityfocus.com/bid/66529 @@ -10463,6 +10465,7 @@ JS MultiHotel 2.2.1 - Multiple Script Direct Request Path Disclosure 105187 + http://packetstormsecurity.com/files/125959/ http://seclists.org/fulldisclosure/2014/Mar/428 FPD @@ -10477,7 +10480,7 @@ FPD - Js-Multi-Hotel 2.2.1 - refreshDate.php roomid Parameter Reflected XSS + JS MultiHotel 2.2.1 - refreshDate.php roomid Parameter Reflected XSS 100575 55919 @@ -11542,6 +11545,7 @@ Media File Renamer v1.7.0 - Persistent XSS 2014-2040 + http://packetstormsecurity.com/files/125378/ http://www.vapid.dhs.org/advisories/wordpress/plugins/MediaFileRenamer-1.7.0/ XSS @@ -11576,6 +11580,7 @@ 103831 57203 + http://packetstormsecurity.com/files/125421/ XSS @@ -11712,6 +11717,7 @@ 2014-2340 104402 + http://packetstormsecurity.com/files/125991/ https://www.htbridge.com/advisory/HTB23206 CSRF @@ -12137,9 +12143,9 @@ - Wordpress Plugin "wp-business-intelligence-lite" Remote Code Execution Exploit + Wordpress Plugin "wp-business-intelligence-lite" - Remote Code Execution Exploit - http://packetstormsecurity.com/files/125927/wpbizintel-shell.txt + http://packetstormsecurity.com/files/125927/ http://cxsecurity.com/issue/WLB-2014030243 RCE @@ -12147,4 +12153,24 @@ + + + Barclaycart - Shell Upload + + http://packetstormsecurity.com/files/125552/ + + UPLOAD + + + + + + Premium Gallery Manager - Shell Upload + + http://packetstormsecurity.com/files/125586/ + + UPLOAD + + + diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index 7266f50a..1304a6ec 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -93,6 +93,13 @@ UPLOAD + + vithy - Custom Background Shell Upload + + http://packetstormsecurity.com/files/125827/ + + UPLOAD + @@ -110,6 +117,13 @@ UPLOAD + + appius - Custom Background Shell Upload + + http://packetstormsecurity.com/files/125827/ + + UPLOAD + @@ -144,6 +158,13 @@ UPLOAD + + Shotzz - Custom Background Shell Upload + + http://packetstormsecurity.com/files/125827/ + + UPLOAD + @@ -154,6 +175,13 @@ UPLOAD + + dagda - Custom Background Shell Upload + + http://packetstormsecurity.com/files/125827/ + + UPLOAD + @@ -1905,6 +1933,13 @@ XSS + + felici - Custom Background Shell Upload + + http://packetstormsecurity.com/files/125830/ + + UPLOAD +