diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 21e7c95d..a474160f 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -253,6 +253,7 @@ All Video Gallery - Multiple SQL Injection Vulnerabilities 50874 + 22427 http://ceriksen.com/2012/11/04/wordpress-all-video-gallery-plugin-sql-injection/ SQLI @@ -1324,11 +1325,24 @@ - Social Discussions - Multiple Vulnerabilities + Social Discussions 6.1.1 - Multiple Script Direct Request Path Disclosure + 86730 + 22158 + http://xforce.iss.net/xforce/xfdb/79465 http://www.waraxe.us/advisory-93.html - MULTI + FPD + + + Social Discussions 6.1.1 - social-discussions-networkpub_ajax.php HTTP_ENV_VARS Parameter Remote File Inclusion + + 86731 + 22158 + http://xforce.iss.net/xforce/xfdb/79464 + http://www.waraxe.us/advisory-93.html + + RFI @@ -3909,7 +3923,7 @@ - SWF Vulnerable to XSS Bundled in Many WordPress Plugins + NextGEN Gallery - SWF Vulnerable to XSS http://brindi.si/g/blog/vulnerable-swf-bundled-in-wordpress-plugins.html 51271 @@ -3918,7 +3932,7 @@ 1.9.8 - swfupload.swf Multiple Cross Site Scripting Vulnerabilities + NextGEN Gallery - swfupload.swf Multiple Cross Site Scripting Vulnerabilities http://www.securityfocus.com/bid/60433 @@ -8189,7 +8203,7 @@ - IndiaNIC Testimonial 2.2 - CSRF vulnerability + IndiaNIC Testimonial 2.2 - Setting Manipulation CSRF 96792 2013-5672 @@ -8200,7 +8214,7 @@ CSRF - IndiaNIC Testimonial 2.2 - SQL Injection vulnerability + IndiaNIC Testimonial 2.2 - testimonial.php custom_query Parameter SQL Injection 96793 2013-5673 @@ -8211,11 +8225,12 @@ SQLI - IndiaNIC Testimonial 2.2 - XSS vulnerability + IndiaNIC Testimonial 2.2 - iNIC_testimonial_save Action Multiple Parameter XSS - http://seclists.org/fulldisclosure/2013/Sep/5 + 96795 28054 http://packetstormsecurity.com/files/123036/ + http://seclists.org/fulldisclosure/2013/Sep/5 XSS @@ -8827,6 +8842,15 @@ XSS 1.4.2 + + A Forms 1.4.0 - a-forms.php aform_css_file_selector() Function css_file_selection Parameter XSS + + 96809 + 54489 + + XSS + 1.4.2 + A Forms 1.4.0 - a-forms.php add_field_to_section Function Multiple Parameter XSS @@ -10516,4 +10540,16 @@ + + + Easy Webinar - get_widget.php wid Parameter SQL Injection + + 86754 + 22300 + + SQLI + 1.6.7 + + +