diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 340188c1..1e25d51a 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -3612,15 +3612,6 @@ XSS 1.9.8 - - NextGEN Gallery <= 1.5.1 - XSS Vulnerability - - 12098 - - XSS - 1.5.2 - - swfupload.swf Multiple Cross Site Scripting Vulnerabilities http://www.securityfocus.com/bid/60433 @@ -3630,13 +3621,94 @@ NextGEN Gallery 1.9.12 - Arbitrary File Upload - http://wordpress.org/plugins/nextgen-gallery/changelog/ 94232 2013-3684 + http://wordpress.org/plugins/nextgen-gallery/changelog/ UPLOAD 1.9.13 + + NextGEN Gallery 1.9.11 - xml/json.php Crafted Request Parsing Path Disclosure + + 90242 + 2013-0291 + 52137 + + UNKNOWN + + + NextGEN Gallery 1.9.5 - gallerypath Parameter Stored XSS + + 97690 + + XSS + + + NextGEN Gallery <= 1.9.0 - admin/manage-galleries.php paged Parameter XSS + + 78363 + 47588 + + XSS + 1.9.1 + + + NextGEN Gallery <= 1.9.0 - admin/manage-images.php paged Parameter XSS + + 78364 + 47588 + + XSS + 1.9.1 + + + NextGEN Gallery <= 1.9.0 - admin/manage.php Multiple Parameter XSS + + 78365 + 47588 + + XSS + 1.9.1 + + + NextGEN Gallery <= 1.8.3 - wp-admin/admin.php search Parameter XSS + + 76576 + 46602 + + XSS + 1.8.4 + + + NextGEN Gallery <= 1.8.3 - Tag Deletion CSRF + + 76577 + 46602 + + CSRF + 1.8.4 + + + NextGEN Gallery <= 1.7.3 - xml/ajax.php Path Disclosure + + 72023 + + FPD + 1.7.4 + + + NextGEN Gallery <= 1.5.1 - xml/media-rss.php mode Parameter XSS + + 63574 + 12098 + 39341 + http://www.securityfocus.com/bid/39250 + + XSS + 1.5.2 + + @@ -6515,20 +6587,23 @@ - Mathjax Latex 1.1 - CSRF Vulnerability + Mathjax Latex 1.1 - Setting Manipulation CSRF - 24889 91737 + 24889 + http://packetstormsecurity.com/files/120931/ http://1337day.com/exploit/20566 CSRF + 1.2 - WP-Banners-Lite - XSS vulnerability + WP-Banners-Lite 1.4.0 - XSS vulnerability + http://packetstormsecurity.com/files/120928/ http://seclists.org/fulldisclosure/2013/Mar/209 http://threatpost.com/en_us/blogs/xss-flaw-wordpress-plugin-allows-injection-malicious-code-032513