added leaflet-maps-marker vulnerabilities (sorry there are no details on the last one it was a pentest at work)

This commit is contained in:
Christian Mehlmauer
2014-03-26 00:54:37 +01:00
parent 13320ea8cc
commit cbcb696cfd

View File

@@ -8543,14 +8543,35 @@
</plugin>
<plugin name="mapsmarker">
<!-- old lite version, not downloadable -->
<vulnerability>
<title>Leaflet Maps Marker - Tag Multiple Parameter SQL Injection</title>
<title>Leaflet Maps Marker - Multiple security issues (this plugin was replaced by a "pro version" with new version numbers so this entry might be a false positive on your system)</title>
<references>
<secunia>49845</secunia>
<url>http://www.mapsmarker.com/2012/06/06/leaflet-maps-marker-v2-4-is-available/</url>
</references>
<type>MULTI</type>
<fixed_in>2.4</fixed_in>
</vulnerability>
<vulnerability>
<title>Leaflet Maps Marker - Tag Multiple Parameter SQL Injection (this plugin was replaced by a "pro version" with new version numbers so this entry might be a false positive on your system)</title>
<references>
<osvdb>94388</osvdb>
<secunia>53855</secunia>
<url>http://www.mapsmarker.com/2013/05/24/v3-5-4-with-lots-of-translation-updates-bugfixes-is-available/</url>
</references>
<type>SQLI</type>
<fixed_in>3.5.4</fixed_in>
</vulnerability>
<!-- New Pro Version -->
<vulnerability>
<title>Leaflet Maps Marker Pro - SQLI, XSS, Shell Upload, file delete</title>
<references>
<url>http://www.mapsmarker.com/2014/03/26/pro-v1-5-8-with-wordpress-3-9-compatibility-improvements-based-on-a-security-audit-by-the-city-of-vienna-is-available/</url>
</references>
<type>MULTI</type>
<fixed_in>1.5.8</fixed_in>
</vulnerability>
</plugin>
<plugin name="xorbin-analog-flash-clock">