From c58d8992cfad25879c23701f497783247999791c Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Fri, 15 Nov 2013 10:37:28 +0100 Subject: [PATCH] Update plugin_vulns.xml --- data/plugin_vulns.xml | 102 +++++++++++++++++++++++++++++++++++++++--- 1 file changed, 97 insertions(+), 5 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index f41ea038..3dfe2a51 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -1603,6 +1603,7 @@ Omni Secure Files 0.1.13 - Arbitrary File Upload 19009 + http://www.securityfocus.com/bid/53872 UPLOAD @@ -1684,12 +1685,22 @@ - Gallery 3.06 - Arbitrary File Upload + Gallery 3.06 - gallery-plugin/upload/php.php File Upload PHP Code Execution + 82661 18998 UPLOAD + + Gallery Plugin 3.8.3 - gallery-plugin.php filename_1 Parameter Arbitrary File Access + + 89124 + http://packetstormsecurity.com/files/119458/ + http://www.securityfocus.com/bid/57256 + http://seclists.org/bugtraq/2013/Jan/45 + + @@ -1990,6 +2001,7 @@ 49189 http://packetstormsecurity.com/files/112688/ + http://www.securityfocus.com/bid/53538 XSS 8.1 @@ -1998,10 +2010,11 @@ - Soundcloud Is Gold <= 2.1 - Cross Site Scripting + Soundcloud Is Gold <= 2.1 - 'action' Parameter Cross Site Scripting Vulnerability 49188 http://packetstormsecurity.com/files/112689/ + http://www.securityfocus.com/bid/53537 XSS @@ -2782,11 +2795,14 @@ - adminimize 1.7.21 - Cross-Site Scripting Vulnerabilities + adminimize 1.7.21 - 'page' Parameter Cross Site Scripting Vulnerability + 2011-4926 + http://www.securityfocus.com/bid/50745 http://seclists.org/bugtraq/2011/Nov/135 XSS + 1.7.22 @@ -4938,8 +4954,9 @@ - browser-rejector - Remote and Local File Inclusion + Browser Rejector - Remote and Local File Inclusion + 89053 51739 LFI @@ -6969,11 +6986,14 @@ - WP Maintenance Mode - Setting Manipulation CSRF + WP Maintenance Mode 1.8.7 - Setting Manipulation CSRF 94450 + 2013-3250 + 53125 CSRF + 1.8.8 @@ -8361,4 +8381,76 @@ + + + TagGator - 'tagid' Parameter SQL Injection Vulnerability + + http://www.securityfocus.com/bid/52908 + + SQLI + + + + + + Uploadify Integration 0.9.6 - Multiple Cross Site Scripting Vulnerabilities + + http://www.securityfocus.com/bid/52944 + + XSS + + + + + WPsc MijnPress - 'rwflush' Parameter Cross Site Scripting Vulnerability + + http://www.securityfocus.com/bid/53302 + + XSS + + + + + + Leaflet Maps Marker 3.5.2 - Two SQL Injection Vulnerabilities + + 53855 + + SQLI + 3.5.3 + + + + + + XML Sitemap Generator 3.2.8 - XML File Overwrite Arbitrary Code Execution + + 89411 + http://packetstormsecurity.com/files/119357/ + + RCE + + + + + + Spam Free Plugin 1.9.2 - Multiple Script Direct Request Path Disclosure + + 88954 + http://xforce.iss.net/xforce/xfdb/81007 + + FPD + + + Spam Free Plugin 1.9.2 - IP Blocklist Restriction Bypass + + 88955 + http://xforce.iss.net/xforce/xfdb/81006 + http://packetstormsecurity.com/files/119274/ + + AUTHBYPASS + + +