From a75dae8128d6c28504a18c33cbd4e7c94d091a1b Mon Sep 17 00:00:00 2001 From: erwanlr Date: Fri, 5 Jul 2013 10:39:38 +0200 Subject: [PATCH] Added vulns & refs --- data/plugin_vulns.xml | 63 +++++++++++++++++++++++++++++++++++++++++++ data/vuln.xsd | 1 + data/wp_vulns.xml | 33 +++++++++++++++++++++++ 3 files changed, 97 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index c503e731..7078c7dd 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -3061,6 +3061,11 @@ http://www.exploit-db.com/exploits/17872/ UPLOAD + + Category Grid View Gallery CatGridPost.php ID Parameter XSS + http://osvdb.org/94805 + XSS + @@ -3282,6 +3287,12 @@ XSS 5.0.3 + + WP Photo Album Plus wp-admin/admin.php edit_id Parameter XSS + http://osvdb.org/94465 + XSS + 5.0.11 + @@ -4862,6 +4873,12 @@ Spider Catalog Plugin Cross-Site Scripting and SQL Injection Vulnerabilities http://secunia.com/advisories/53491/ http://osvdb.org/93591 + http://osvdb.org/93593 + http://osvdb.org/93594 + http://osvdb.org/93595 + http://osvdb.org/93596 + http://osvdb.org/93597 + http://osvdb.org/93598 MULTI @@ -4871,6 +4888,11 @@ Spider Event Calendar Plugin Security Bypass, Cross-Site Scripting and SQLi Vulnerabilities http://secunia.com/advisories/53481/ http://osvdb.org/93584 + http://osvdb.org/93585 + http://osvdb.org/93586 + http://osvdb.org/93587 + http://osvdb.org/93588 + http://osvdb.org/93582 MULTI @@ -4924,4 +4946,45 @@ + + + Dropdown Menu Widget Script Insertion CSRF + http://osvdb.org/94771 + CSRF + + + + + + Feed news_dt.php nid Parameter SQL Injection + http://osvdb.org/94804 + SQLI + + + + + + BuddyPress Extended Friendship Request wp-admin/admin-ajax.php friendship_request_message Parameter XSS + http://osvdb.org/94807 + XSS + 1.0.2 + + + + + + wp-private-messages /wp-admin/profile.php msgid Parameter SQL Injection + http://osvdb.org/94702 + SQLI + + + + + + Stream Video Player Plugin for WordPress Setting Manipulation CSRF + http://osvdb.org/94466 + CSRF + + + diff --git a/data/vuln.xsd b/data/vuln.xsd index 146d2a7c..6c344184 100644 --- a/data/vuln.xsd +++ b/data/vuln.xsd @@ -26,6 +26,7 @@ + diff --git a/data/wp_vulns.xml b/data/wp_vulns.xml index d103d979..328342cf 100644 --- a/data/wp_vulns.xml +++ b/data/wp_vulns.xml @@ -11,6 +11,39 @@ http://osvdb.org/94235 UNKNOWN + + WordPress Multiple XSS + http://osvdb.org/94791 + http://osvdb.org/94785 + http://osvdb.org/94786 + http://osvdb.org/94790 + XSS + + + WordPress TinyMCE Plugin Flash Applet Unspecified Spoofing Weakness + http://osvdb.org/94787 + UNKNOWN + + + WordPress File Upload Unspecified Path Disclosure + http://osvdb.org/94788 + UNKNOWN + + + WordPress oEmbed Unspecified XML External Entity (XXE) Arbitrary File Disclosure + http://osvdb.org/94789 + XXE + + + WordPress Multiple Role Remote Privilege Escalation + http://osvdb.org/94783 + UNKNOWN + + + WordPress HTTP API Unspecified Server Side Request Forgery (SSRF) + http://osvdb.org/94784 + SSRF +