From 8ca50428f165a02531459948d5a26fd10dc6d6e6 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Wed, 9 Oct 2013 11:41:27 +0200 Subject: [PATCH 1/2] Update plugin_vulns.xml --- data/plugin_vulns.xml | 113 ++++++++++++++++++++++++++++++++++++++---- 1 file changed, 104 insertions(+), 9 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index c2a91c6c..62c952f3 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -965,12 +965,20 @@ MULTI - WordPress Spider Catalog Plugin Multiple SQL Injection and Cross Site Scripting Vulnerabilities + Spider Catalog - Multiple SQL Injection and Cross Site Scripting Vulnerabilities http://www.securityfocus.com/bid/60079/info MULTI + + Spider Catalog Plugin 1.4.6 - Multiple Vulnerabilities + + 25724 + 93591 + + MULTI + @@ -3335,16 +3343,18 @@ - Wp-FileManager 1.2 Remote Upload Vulnerability + wp-FileManager 1.2 - Remote Upload Vulnerability 4844 UPLOAD - WordPress wp-FileManager File Download Vulnerability + wp-FileManager 1.3.0 - File Download Vulnerability 53421 + 25440 + 93446 UNKNOWN 1.4.0 @@ -4355,7 +4365,7 @@ - W3-Total-Cache Username and Hash Extract + W3 Total Cache - Username and Hash Extract http://seclists.org/fulldisclosure/2012/Dec/242 https://github.com/FireFart/W3TotalCacheExploit @@ -4365,7 +4375,7 @@ 0.9.2.5 - W3-Total-Cache Remote Code Execution + W3 Total Cache - Remote Code Execution http://www.acunetix.com/blog/web-security-zone/wp-plugins-remote-code-execution/ http://wordpress.org/support/topic/pwn3d @@ -4377,6 +4387,15 @@ RCE 0.9.2.9 + + W3 Total Cache 0.9.2.9 - PHP Code Execution + + 25137 + 2013-2010 + 92652 + 53052 + + @@ -4730,12 +4749,21 @@ - WordPress Spider Calendar Plugin "many_sp_calendar" Cross-Site Scripting Vulnerability + Spider Calendar Plugin "many_sp_calendar" Cross-Site Scripting Vulnerability 50981 XSS + + Spider Calendar 1.3.0 - Multiple Vulnerabilities + + 25723 + 93584 + 53481 + + + @@ -5705,11 +5733,14 @@ - WP FuneralPress - Stored XSS in Guestbook + FuneralPress 1.1.6 - Persistent XSS + 24914 + 2013-3529 + 91868 http://seclists.org/fulldisclosure/2013/Mar/282 - XSS + @@ -6365,9 +6396,10 @@ - ultimate Auction Auction Creation CSRF + Ultimate Auction 1.0 - CSRF Vulnerability 94407 + 26240 CSRF @@ -6529,6 +6561,7 @@ 96110 96111 54402 + 27531 2.0.11 @@ -6543,6 +6576,7 @@ 96110 96111 54402 + 27531 2.0.11 @@ -6800,6 +6834,8 @@ NOSpamPTI 2.1 - Blind SQL Injection + 28485 + 2013-5917 http://packetstormsecurity.com/files/123331/ SQLI @@ -6856,4 +6892,63 @@ + + + ProPlayer 4.7.9.1 - SQL Injection + + 25605 + 93564 + + SQLI + + + + + + Usernoise 3.7.8 - Persistent XSS Vulnerability + + 27403 + 96000 + + XSS + 3.7.9 + + + + + + Booking Calendar 4.1.4 - CSRF Vulnerability + + 27399 + 96088 + http://wpbookingcalendar.com/ + + CSRF + 4.1.6 + + + + + + ThinkIT 0.1 - Multiple Vulnerabilities + + 27751 + 96515 + http://packetstormsecurity.com/files/122898/ + + MULTI + + + + + + Quick Contact Form Plugin 6.0 - Persistent XSS + + 28808 + http://quick-plugins.com/quick-contact-form/ + + XSS + + + From 90d48feef2d476eb99e4d20aec9360c929dd0341 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Wed, 9 Oct 2013 11:57:50 +0200 Subject: [PATCH 2/2] Fixed some errors --- data/plugin_vulns.xml | 22 ++++++---------------- 1 file changed, 6 insertions(+), 16 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 62c952f3..2034321e 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -4762,7 +4762,7 @@ 93584 53481 - + MULTI @@ -5740,7 +5740,7 @@ 91868 http://seclists.org/fulldisclosure/2013/Mar/282 - + XSS @@ -6616,11 +6616,13 @@ - XSS vulnerability in Usernoise 3.7.8 + Usernoise 3.7.8 - Persistent XSS Vulnerability http://wordpress.org/plugins/usernoise/changelog/ - 27403 + 27403 + 96000 + XSS 3.7.9 @@ -6903,18 +6905,6 @@ - - - Usernoise 3.7.8 - Persistent XSS Vulnerability - - 27403 - 96000 - - XSS - 3.7.9 - - - Booking Calendar 4.1.4 - CSRF Vulnerability