From 6fedeffe03ec8e1a95916e291d9c41e75198401b Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Fri, 25 Oct 2013 16:59:35 +0200 Subject: [PATCH 1/7] Added some 'old' OSVDB vulns --- data/plugin_vulns.xml | 31 ++++++++++++++++++++++++++----- 1 file changed, 26 insertions(+), 5 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 106e4793..1cefdadf 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -1162,6 +1162,8 @@ SimpleMail 1.0.6 - Stored XSS + 84534 + 2012-2579 20361 50208 @@ -1173,10 +1175,13 @@ Postie 1.4.3 - Stored XSS + 84532 + 2012-2580 20360 50207 XSS + 1.5.15 @@ -5119,8 +5124,18 @@ - Vitamin - Two Arbitrary File Disclosure Vulnerabilities + Vitamin 1.0 - add_headers.php path Parameter Traversal Arbitrary File Access + 84463 + 50176 + + LFI + 1.1 + + + Vitamin 1.0 - minify.php path Parameter Traversal Arbitrary File Access + + 84464 50176 LFI @@ -5130,8 +5145,9 @@ - Featured Post with thumbnail - Unspecified timthumb Vulnerability + Featured Post with thumbnail 1.4 - Unspecified timthumb Vulnerability + 84460 50161 UNKNOWN @@ -5141,8 +5157,10 @@ - WP Lead Management - Script Insertion Vulnerabilities + WP Lead Management 3.0.0 - Script Insertion Vulnerabilities + 84462 + 20270 50166 XSS @@ -5165,7 +5183,9 @@ G-Lock Double Opt-in Manager - Two Security Bypass Vulnerabilities + 84434 50100 + http://packetstormsecurity.org/files/115173/ AUTHBYPASS @@ -6139,8 +6159,9 @@ - syntaxhighlighter - clipboard.swf XSS + SyntaxHighlighter Evolved 3.1.5 - clipboard.swf Unspecified XSS + 92848 53235 XSS @@ -6161,7 +6182,7 @@ - easy-adsense-lite 6.06 - CSRF + Easy AdSense Lite 6.06 - Setting Manipulation CSRF 92910 2013-2702 From 803a5a740900f617d41f7f086810f0a0f91ea2e0 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sat, 26 Oct 2013 20:57:48 +0200 Subject: [PATCH 2/7] Update plugin_vulns.xml --- data/plugin_vulns.xml | 44 +++++++++++++++++++++++++++++++++++++++---- 1 file changed, 40 insertions(+), 4 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 1cefdadf..aad4889d 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -7524,10 +7524,12 @@ - wp-realty - MySQL Time Based Injection + WP Realty - MySQL Time Based Injection + 98748 29021 - http://www.exploit-db.com/exploits/29021/ + http://packetstormsecurity.com/files/123655/ + http://www.securityfocus.com/bid/63217 SQLI @@ -7601,11 +7603,22 @@ - Blue Wrench Video-Widget CSRF and Persistent XSS 0day Disclosure + Blue Wrench Video Widget 1.0.2 - admin.php bw-videos Page Multiple Action CSRF + 98922 + 55456 http://securityundefined.com/wordpress-plugin-blue-wrench-video-widget-csrf-persistent-xss-0day-disclosure/ - MULTI + CSRF + + + Blue-Wrench-Video-Widget 1.0.2 - admin.php bw-videos Page Multiple Parameter Stored XSS + + 98923 + 55456 + http://securityundefined.com/wordpress-plugin-blue-wrench-video-widget-csrf-persistent-xss-0day-disclosure/ + + XSS @@ -7641,4 +7654,27 @@ + + + Payment Gateways Caller for WP e-Commerce 0.1.0 - load_merchant Parameter Traversal Local file Inclusion + + 98916 + http://packetstormsecurity.com/files/123744/ + + LFI + 0.1.1 + + + + + + Easy Photo Album 1.1.5 - Album Information Disclosure + + 98802 + + AUTHBYPASS + 1.1.6 + + + From bc14c6d040069761415f85563ad9460eba18bb61 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sat, 26 Oct 2013 21:09:00 +0200 Subject: [PATCH 3/7] Fixed tag error --- data/plugin_vulns.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index aad4889d..8c7268ed 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -5147,7 +5147,7 @@ Featured Post with thumbnail 1.4 - Unspecified timthumb Vulnerability - 84460 + 84460 50161 UNKNOWN From 5f2edac86a61ed0471c45a0b65e117faea80f68f Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sat, 26 Oct 2013 22:00:43 +0200 Subject: [PATCH 4/7] Update plugin_vulns.xml --- data/plugin_vulns.xml | 22 +++++++++++++++++++--- 1 file changed, 19 insertions(+), 3 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 8c7268ed..fe63acd5 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -4688,19 +4688,23 @@ - Cardoza WordPress poll - Cross-Site Request Forgery Vulnerability + Cardoza WordPress poll 34.05 - Multiple External Function Remote Poll Manipulation 89443 2013-1401 51925 + http://seclists.org/bugtraq/2013/Jan/86 + http://packetstormsecurity.com/files/119736/ CSRF 34.06 - Cardoza WordPress poll - Multiple SQL injection vulnerabilities + Cardoza WordPress poll - CWPPoll.js Multiple Method pollid Parameter SQL Injection - 51942 + 89444 + 2013-1400 + http://packetstormsecurity.com/files/119736/ http://www.girlinthemiddle.net/2013/01/multiple-sql-injection-vulnerabilities.html http://seclists.org/bugtraq/2013/Jan/86 @@ -7677,4 +7681,16 @@ + + + Hungred Post Thumbnail - hpt_file_upload.php File Upload PHP Code Execution + + 82830 + http://packetstormsecurity.com/files/113402/ + http://www.securityfocus.com/bid/53898 + + RCE + + + From 30e4fe2671d201de6e3197c346c7212bcf225905 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sat, 26 Oct 2013 22:28:46 +0200 Subject: [PATCH 5/7] Update plugin_vulns.xml --- data/plugin_vulns.xml | 19 ++++++++++++++++++- 1 file changed, 18 insertions(+), 1 deletion(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index fe63acd5..daac5c61 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -1337,6 +1337,20 @@ + + + VideoWhisper Live Streaming Integration - ls/htmlchat.php Multiple Parameter XSS + + 96593 + 2013-5714 + 54619 + http://www.securityfocus.com/bid/61977 + http://seclists.org/bugtraq/2013/Aug/163 + + XSS + + + Auctions 2.0.1.3 - Arbitrary @@ -7109,7 +7123,9 @@ <vulnerability> <title>Comment Attachment 1.0 - XSS Vulnerability + 97600 http://packetstormsecurity.com/files/123327/ + http://www.securityfocus.com/bid/62438 XSS @@ -7119,6 +7135,7 @@ Mukioplayer 1.6 - SQL Injection + 97609 http://packetstormsecurity.com/files/123231/ SQLI @@ -7324,7 +7341,7 @@ - A Forms 1.4.0 Multiple Parameters SQL Injection + A Forms 1.4.0 - Multiple Parameters SQL Injection 96404 From 77ee2494f04b9234004c8461e55025781b21c21a Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sat, 26 Oct 2013 23:09:42 +0200 Subject: [PATCH 6/7] Update plugin_vulns.xml --- data/plugin_vulns.xml | 17 ++++++++++++++++- 1 file changed, 16 insertions(+), 1 deletion(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index daac5c61..b967b334 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -1337,7 +1337,7 @@ - + VideoWhisper Live Streaming Integration - ls/htmlchat.php Multiple Parameter XSS @@ -7710,4 +7710,19 @@ + + + Download Monitor 3.3.6.1 - wp-admin/admin.php Multiple Parameter XSS + + 95613 + 2013-3262 + 2013-5098 + 53116 + http://www.securityfocus.com/bid/61407 + + XSS + 3.3.6.2 + + + From fa9f4c0ab78e213731dbc08803b9ab674755f2ba Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sun, 27 Oct 2013 00:09:33 +0200 Subject: [PATCH 7/7] Update plugin_vulns.xml --- data/plugin_vulns.xml | 21 ++++----------------- 1 file changed, 4 insertions(+), 17 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index b967b334..b3a91b51 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -2010,12 +2010,14 @@ - Download Monitor < 3.3.6.2 - Cross Site Scripting + Download Monitor <= 3.3.6.1 - Cross Site Scripting http://www.securityfocus.com/bid/61407 - 53116 + 95613 2013-5098 2013-3262 + 53116 + http://www.securityfocus.com/bid/61407 XSS 3.3.6.2 @@ -7710,19 +7712,4 @@ - - - Download Monitor 3.3.6.1 - wp-admin/admin.php Multiple Parameter XSS - - 95613 - 2013-3262 - 2013-5098 - 53116 - http://www.securityfocus.com/bid/61407 - - XSS - 3.3.6.2 - - -