diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 106e4793..b3a91b51 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -1162,6 +1162,8 @@ SimpleMail 1.0.6 - Stored XSS + 84534 + 2012-2579 20361 50208 @@ -1173,10 +1175,13 @@ Postie 1.4.3 - Stored XSS + 84532 + 2012-2580 20360 50207 XSS + 1.5.15 @@ -1332,6 +1337,20 @@ + + + VideoWhisper Live Streaming Integration - ls/htmlchat.php Multiple Parameter XSS + + 96593 + 2013-5714 + 54619 + http://www.securityfocus.com/bid/61977 + http://seclists.org/bugtraq/2013/Aug/163 + + XSS + + + Auctions 2.0.1.3 - Arbitrary @@ -1991,12 +2010,14 @@ <plugin name="download-monitor"> <vulnerability> - <title>Download Monitor < 3.3.6.2 - Cross Site Scripting + Download Monitor <= 3.3.6.1 - Cross Site Scripting http://www.securityfocus.com/bid/61407 - 53116 + 95613 2013-5098 2013-3262 + 53116 + http://www.securityfocus.com/bid/61407 XSS 3.3.6.2 @@ -4683,19 +4704,23 @@ - Cardoza WordPress poll - Cross-Site Request Forgery Vulnerability + Cardoza WordPress poll 34.05 - Multiple External Function Remote Poll Manipulation 89443 2013-1401 51925 + http://seclists.org/bugtraq/2013/Jan/86 + http://packetstormsecurity.com/files/119736/ CSRF 34.06 - Cardoza WordPress poll - Multiple SQL injection vulnerabilities + Cardoza WordPress poll - CWPPoll.js Multiple Method pollid Parameter SQL Injection - 51942 + 89444 + 2013-1400 + http://packetstormsecurity.com/files/119736/ http://www.girlinthemiddle.net/2013/01/multiple-sql-injection-vulnerabilities.html http://seclists.org/bugtraq/2013/Jan/86 @@ -5119,8 +5144,18 @@ - Vitamin - Two Arbitrary File Disclosure Vulnerabilities + Vitamin 1.0 - add_headers.php path Parameter Traversal Arbitrary File Access + 84463 + 50176 + + LFI + 1.1 + + + Vitamin 1.0 - minify.php path Parameter Traversal Arbitrary File Access + + 84464 50176 LFI @@ -5130,8 +5165,9 @@ - Featured Post with thumbnail - Unspecified timthumb Vulnerability + Featured Post with thumbnail 1.4 - Unspecified timthumb Vulnerability + 84460 50161 UNKNOWN @@ -5141,8 +5177,10 @@ - WP Lead Management - Script Insertion Vulnerabilities + WP Lead Management 3.0.0 - Script Insertion Vulnerabilities + 84462 + 20270 50166 XSS @@ -5165,7 +5203,9 @@ G-Lock Double Opt-in Manager - Two Security Bypass Vulnerabilities + 84434 50100 + http://packetstormsecurity.org/files/115173/ AUTHBYPASS @@ -6139,8 +6179,9 @@ - syntaxhighlighter - clipboard.swf XSS + SyntaxHighlighter Evolved 3.1.5 - clipboard.swf Unspecified XSS + 92848 53235 XSS @@ -6161,7 +6202,7 @@ - easy-adsense-lite 6.06 - CSRF + Easy AdSense Lite 6.06 - Setting Manipulation CSRF 92910 2013-2702 @@ -7084,7 +7125,9 @@ Comment Attachment 1.0 - XSS Vulnerability + 97600 http://packetstormsecurity.com/files/123327/ + http://www.securityfocus.com/bid/62438 XSS @@ -7094,6 +7137,7 @@ Mukioplayer 1.6 - SQL Injection + 97609 http://packetstormsecurity.com/files/123231/ SQLI @@ -7299,7 +7343,7 @@ - A Forms 1.4.0 Multiple Parameters SQL Injection + A Forms 1.4.0 - Multiple Parameters SQL Injection 96404 @@ -7503,10 +7547,12 @@ - wp-realty - MySQL Time Based Injection + WP Realty - MySQL Time Based Injection + 98748 29021 - http://www.exploit-db.com/exploits/29021/ + http://packetstormsecurity.com/files/123655/ + http://www.securityfocus.com/bid/63217 SQLI @@ -7580,11 +7626,22 @@ - Blue Wrench Video-Widget CSRF and Persistent XSS 0day Disclosure + Blue Wrench Video Widget 1.0.2 - admin.php bw-videos Page Multiple Action CSRF + 98922 + 55456 http://securityundefined.com/wordpress-plugin-blue-wrench-video-widget-csrf-persistent-xss-0day-disclosure/ - MULTI + CSRF + + + Blue-Wrench-Video-Widget 1.0.2 - admin.php bw-videos Page Multiple Parameter Stored XSS + + 98923 + 55456 + http://securityundefined.com/wordpress-plugin-blue-wrench-video-widget-csrf-persistent-xss-0day-disclosure/ + + XSS @@ -7620,4 +7677,39 @@ + + + Payment Gateways Caller for WP e-Commerce 0.1.0 - load_merchant Parameter Traversal Local file Inclusion + + 98916 + http://packetstormsecurity.com/files/123744/ + + LFI + 0.1.1 + + + + + + Easy Photo Album 1.1.5 - Album Information Disclosure + + 98802 + + AUTHBYPASS + 1.1.6 + + + + + + Hungred Post Thumbnail - hpt_file_upload.php File Upload PHP Code Execution + + 82830 + http://packetstormsecurity.com/files/113402/ + http://www.securityfocus.com/bid/53898 + + RCE + + +