diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index b6749104..3cd341cf 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -3544,7 +3544,7 @@ XSS - + WordPress Flexi Quote Rotator Plugin < 0.9.2 Cross-Site Request Forgery and SQL Injection Vulnerabilities @@ -3552,7 +3552,7 @@ MULTI - + WordPress Get Off Malicious Scripts < 1.2.07.20 Cross-Site Scripting Vulnerability @@ -3560,7 +3560,7 @@ XSS - + WordPress Cimy User Extra Fields Plugin < 2.3.9 Arbitrary File Upload Vulnerability @@ -3568,7 +3568,7 @@ UPLOAD - + WordPress Nmedia Users File Uploader Plugin < 2.0 Arbitrary File Upload Vulnerability @@ -3584,7 +3584,7 @@ UPLOAD - + accordion Arbitrary File Upload Vulnerability @@ -3592,7 +3592,7 @@ UPLOAD - + wp-catpro Arbitrary File Upload Vulnerability @@ -3600,7 +3600,7 @@ UPLOAD - + Wordpress RLSWordPressSearch plugin SQL Injection @@ -3608,7 +3608,7 @@ SQLI - + wordpress-simple-shout-box Plugin SQL Injection @@ -3616,7 +3616,7 @@ SQLI - + Wordpress portfolio-slideshow-pro v3 Plugin SQL Injection @@ -3624,7 +3624,7 @@ SQLI - + WordPress Simple History Plugin < 1.0.8 RSS Feed "rss_secret" Disclosure Weakness @@ -3632,7 +3632,7 @@ UNKNOWN - + WordPress p1m media manager plugin SQL Injection Vulnerability @@ -3640,7 +3640,7 @@ SQLI - + Wordpress wp-table-reloaded plugin < 1.9.4 cross-site scripting in SWF @@ -3650,7 +3650,7 @@ XSS - + WordPress Gallery Plugin "load" Remote File Inclusion Vulnerability @@ -3658,7 +3658,7 @@ RFI - + Wordpress plugins ForumConverter SQL Injection Vulnerability @@ -3666,7 +3666,7 @@ SQLI - + WordPress plugins Newsletter SQL Injection Vulnerability @@ -3674,7 +3674,7 @@ SQLI - + Cross-Site Scripting (XSS) Vulnerability in CommentLuv WordPress Plugin < 2.92.4 @@ -3686,7 +3686,7 @@ XSS - + Wordpress wp-forum plugin SQL Injection @@ -3694,7 +3694,7 @@ SQLI - + WordPress WP ecommerce Shop Styling Plugin < 1.8 "dompdf" Remote File Inclusion Vulnerability @@ -3702,7 +3702,7 @@ RFI - + Wordpress Audio Player Plugin < 2.0.4.6 XSS in SWF @@ -3711,7 +3711,7 @@ XSS - + Wordpress plugin CKEditor 4.0 Arbitrary File Upload Exploit @@ -3719,7 +3719,7 @@ UPLOAD - + wordpress myftp-ftp-like-plugin-for-wordpress plugin v2 Plugin SQL Injection @@ -3727,7 +3727,7 @@ SQLI - + WordPress WP Online Store Plugin 1.3.1 downloaded before 2013-01-17 File Disclosure and File Inclusion Vulnerabilities @@ -3753,17 +3753,17 @@ XSS - + smart-flv jwplayer.swf XSS http://www.openwall.com/lists/oss-security/2013/02/24/7 http://packetstormsecurity.com/files/115100/jwplayer-xss.txt - http://osvdb.org/72794 + http://osvdb.org/90606 XSS - + - + Google Alert And Twitter v.3.1.5 XSS Exploit, SQL Injection @@ -3771,5 +3771,5 @@ MULTI - +