diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 4219dd7d..a3a95545 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -173,6 +173,15 @@ + + Thank You Counter Button 1.8.7 - wp-admin/options.php Multiple Parameter Stored XSS + + 103778 + http://packetstormsecurity.com/files/125397/ + http://www.securityfocus.com/bid/65805 + + XSS + Thank You Counter Button <= 1.8.2 - XSS @@ -1645,6 +1654,87 @@ + + VideoWhisper Live Streaming Integration 4.27.3 - ls/vc_chatlog.php msg Parameter Stored XSS + + 103821 + 2014-1906 + https://www.htbridge.com/advisory/HTB23199 + + XSS + 4.29.5 + + + VideoWhisper Live Streaming Integration 4.27.3 - ls/v_status.php ct Parameter Reflected XSS + + 103820 + 2014-1906 + https://www.htbridge.com/advisory/HTB23199 + + XSS + 4.29.5 + + + VideoWhisper Live Streaming Integration 4.27.3 - ls/lb_logout.php message Parameter Reflected XSS + + 103819 + 2014-1906 + https://www.htbridge.com/advisory/HTB23199 + + XSS + 4.29.5 + + + VideoWhisper Live Streaming Integration 4.27.3 - ls/videotext.php n Parameter Reflected XSS + + 103818 + 2014-1906 + https://www.htbridge.com/advisory/HTB23199 + + XSS + 4.29.5 + + + VideoWhisper Live Streaming Integration 4.27.3 - ls/video.php n Parameter Reflected XSS + + 103817 + 2014-1906 + https://www.htbridge.com/advisory/HTB23199 + + XSS + 4.29.5 + + + VideoWhisper Live Streaming Integration 4.27.3 - ls/htmlchat.php n Parameter Reflected XSS + + 103816 + 2014-1906 + https://www.htbridge.com/advisory/HTB23199 + + XSS + 4.29.5 + + + VideoWhisper Live Streaming Integration 4.27.3 - ls/rtmp_logout.php s Parameter Path Traversal Remote File Deletion + + 103815 + 2014-1907 + http://packetstormsecurity.com/files/125454/ + https://www.htbridge.com/advisory/HTB23199 + + UNKNOWN + 4.29.5 + + + VideoWhisper Live Streaming Integration 4.27.3 - ls/channel.php n Parameter Reflected XSS + + 103814 + 2014-1906 + https://www.htbridge.com/advisory/HTB23199 + + XSS + 4.29.5 + VideoWhisper Live Streaming Integration 4.27.3 - Error Message Unspecified Remote Information Disclosure @@ -7932,6 +8022,15 @@ + + Feedweb 2.4 - feedweb_settings.php _wp_http_referer Parameter DOM-based XSS + + 103788 + 57108 + http://www.securityfocus.com/bid/65800 + + XSS + Feedweb 1.8.8 - widget_remove.php wp_post_id Parameter XSS @@ -10511,6 +10610,15 @@ + + Easy Media Gallery 1.2.29 - wp-admin/edit.php Multiple Parameter Stored XSS + + 103779 + http://packetstormsecurity.com/files/125396/ + http://www.securityfocus.com/bid/65804 + + XSS + Easy Media Gallery 1.2.25 - includes/emg-settings.php spg_add_admin Function Admin User Creation CSRF @@ -11095,4 +11203,52 @@ + + + Alpine PhotoTile For Instagram 1.2.6.5 - wp-admin/options-general.php general_lightbox_params Parameter XSS Weakness + + 103822 + 57198 + http://packetstormsecurity.com/files/125418/ + + XSS + + + + + + Widget Control Powered By Everyblock 1.0.1 - wp-admin/admin.php idDropdown Parameter XSS Weakness + + 103831 + 57203 + + XSS + + + + + + Search Everything 7.0.2 - search-everything.php s Parameter SQL Injection + + 103718 + 56802 + http://www.securityfocus.com/bid/65765 + + SQLI + 7.0.3 + + + + + + Zedity 2.5 - wp-admin/admin-ajax.php zedity_ajax Action zaction Parameter XSS + + 103789 + 57026 + http://www.securityfocus.com/bid/65799 + + XSS + + +