diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 63f4ca4f..68dfc20c 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -2742,16 +2742,20 @@ SQLI - WP Symposium - "u" XSS + WP Symposium 13.02 - wp-symposium/invite.php u Parameter XSS + 92275 + 2013-2695 52864 XSS 13.04 - WP Symposium - "u" Redirection Weakness + WP Symposium 13.02 - invite.php u Parameter Arbitrary Site Redirect + 92274 + 2013-2694 52925 REDIRECT @@ -6225,7 +6229,7 @@ - social-media-widget - malicious code + Social Media Widget - malicious code http://plugins.trac.wordpress.org/changeset?reponame=&old=691839%40social-media-widget%2Ftrunk&new=693941%40social-media-widget%2Ftrunk http://slashdot.org/submission/2592777/top-wordpress-widget-sold-off-turned-into-seo-spambot @@ -6233,6 +6237,17 @@ UNKNOWN 4.0.2 + + Social Media Widget 4.0 - social-widget.php MITM Weakness Arbitrary Code Injection + + 92312 + 2013-1949 + 53020 + http://seclists.org/oss-sec/2013/q2/10 + + UNKNOWN + 4.0.1 + @@ -6327,8 +6342,9 @@ - top-10 - CSRF + top-10 1.9.2 - Setting Manipulation CSRF + 92849 53205 CSRF @@ -6461,8 +6477,9 @@ - Contextual Related Posts - Cross-Site Request Forgery Vulnerability + Contextual Related Posts 1.8.6 - Cross-Site Request Forgery Vulnerability + 93088 52960 CSRF @@ -6472,8 +6489,10 @@ - Calendar - Cross-Site Request Forgery Vulnerability + Calendar 1.3.2 - Entry Addition CSRF + 93025 + 2013-2698 52841 CSRF @@ -7256,6 +7275,7 @@ XSS + LBG Zoominoutslider - add_banner.php Unspecified XSS 99320