From ab51b0536b858fb5efbcdaec2ab58ea1d8ea10b1 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sun, 6 Oct 2013 12:26:51 +0200 Subject: [PATCH 1/4] Added OSVDB #98078 --- data/plugin_vulns.xml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 26760d7d..eb7b9abf 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -1684,6 +1684,14 @@ + + Sharebar <= 1.2.5 sharebar-admin.php page Parameter XSS + + 98078 + http://packetstormsecurity.org/files/123365/ + + XSS + Sharebar <= 1.2.5 Button Manipulation CSRF From 254b4084b734214e03e8414da4eb80dc0be9ee66 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sun, 6 Oct 2013 12:38:36 +0200 Subject: [PATCH 2/4] Added OSVDB #98027 --- data/plugin_vulns.xml | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index eb7b9abf..1c3df250 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -6548,4 +6548,14 @@ + + + + New Post Title Field Stored XSS + + 98027 + + XSS + + From 0fc85e212ab03d15a92f1f0167e21e734a0d87fb Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sun, 6 Oct 2013 13:07:17 +0200 Subject: [PATCH 3/4] Update Mingle Forum vulns. --- data/plugin_vulns.xml | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 1c3df250..15009696 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -2760,8 +2760,6 @@ 16144 - - MULTI @@ -2775,14 +2773,14 @@ MULTI - Mingle Forum plugin <= 1.0.31 SQL Injection Vulnerability + Mingle Forum <= 1.0.31 SQL Injection Vulnerability 17894 SQLI - Mingle Forum (Plugin) <= 1.0.26 Multiple Vulnerabilities + Mingle Forum <= 1.0.26 Multiple Vulnerabilities 15943 @@ -2803,7 +2801,7 @@ SQLI - Privilege Escalation CSRF + Mingle Forum 1.0.35 Privilege Escalation CSRF 96905 2013-0736 From c4881490a0b2603f4c2b5cfbf31e0bb84ebb699b Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sun, 6 Oct 2013 13:38:34 +0200 Subject: [PATCH 4/4] Added OSVDB #97991 --- data/plugin_vulns.xml | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 15009696..ba9e5b41 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -6556,4 +6556,15 @@ XSS + + + + Simple Flickr Display Username Field Stored XSS + + 97991 + + XSS + + +