From 5bee1f1ffdc42719b6f5c2dde69670f179f840ac Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Mon, 7 Oct 2013 20:43:38 +0200 Subject: [PATCH 1/4] Added Secunia #54979 --- data/plugin_vulns.xml | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 2e5c469b..a183d253 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -6624,4 +6624,15 @@ + + + miniAudioPlayer - Two XSS Vulnerabilities + + 54979 + http://packetstormsecurity.com/files/123372/wpminiaudioplayer-xss.txt + + XSS + + + From 828f8c48eb57edc97a8d26b5f09b8f10b9c5546e Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Mon, 7 Oct 2013 20:53:08 +0200 Subject: [PATCH 2/4] Added Secunia #54865 --- data/plugin_vulns.xml | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index a183d253..b0d7bf1f 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -6635,4 +6635,14 @@ + + + Custom Website Data - XSS Vulnerability + + 54865 + + XSS + + + From db91d5041ca503c7d939d5d7a13be1ddf420a41a Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Mon, 7 Oct 2013 22:11:09 +0200 Subject: [PATCH 3/4] Update wp_vulns.xml --- data/wp_vulns.xml | 24 ++++++++++++------------ 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/data/wp_vulns.xml b/data/wp_vulns.xml index 659d12f5..8d9cf491 100644 --- a/data/wp_vulns.xml +++ b/data/wp_vulns.xml @@ -79,7 +79,7 @@ 3.5.2 - WordPress 3.4-3.5.1 DoS in class-phpass.php + WordPress 3.4 - 3.5.1 DoS in class-phpass.php http://seclists.org/fulldisclosure/2013/Jun/65 53676 @@ -146,7 +146,7 @@ 3.5.2 - WordPress 3.4-3.5.1 DoS in class-phpass.php + WordPress 3.4 - 3.5.1 DoS in class-phpass.php http://seclists.org/fulldisclosure/2013/Jun/65 53676 @@ -156,7 +156,7 @@ UNKNOWN - WordPress 3.5 to 3.3.2 Cross-Site Scripting (XSS) (Issue 3) + WordPress 3.3.2 - 3.5 Cross-Site Scripting (XSS) (Issue 3) https://github.com/wpscanteam/wpscan/wiki/WordPress-3.5-Issues @@ -189,7 +189,7 @@ 3.5.2 - WordPress 3.4-3.5.1 DoS in class-phpass.php + WordPress 3.4 - 3.5.1 DoS in class-phpass.php http://seclists.org/fulldisclosure/2013/Jun/65 53676 @@ -199,7 +199,7 @@ UNKNOWN - WordPress 3.5 to 3.3.2 Cross-Site Scripting (XSS) (Issue 3) + WordPress 3.3.2 - 3.5 Cross-Site Scripting (XSS) (Issue 3) https://github.com/wpscanteam/wpscan/wiki/WordPress-3.5-Issues @@ -239,7 +239,7 @@ 3.5.2 - WordPress 3.4-3.5.1 DoS in class-phpass.php + WordPress 3.4 - 3.5.1 DoS in class-phpass.php http://seclists.org/fulldisclosure/2013/Jun/65 53676 @@ -249,7 +249,7 @@ UNKNOWN - WordPress 3.5 to 3.3.2 Cross-Site Scripting (XSS) (Issue 3) + WordPress 3.3.2 to 3.5 Cross-Site Scripting (XSS) (Issue 3) https://github.com/wpscanteam/wpscan/wiki/WordPress-3.5-Issues @@ -282,7 +282,7 @@ 3.5.2 - WordPress 3.4-3.5.1 DoS in class-phpass.php + WordPress 3.4 - 3.5.1 DoS in class-phpass.php http://seclists.org/fulldisclosure/2013/Jun/65 53676 @@ -292,7 +292,7 @@ UNKNOWN - WordPress 3.5 to 3.3.2 Cross-Site Scripting (XSS) (Issue 3) + WordPress 3.3.2 to 3.5 Cross-Site Scripting (XSS) (Issue 3) https://github.com/wpscanteam/wpscan/wiki/WordPress-3.5-Issues @@ -316,7 +316,7 @@ - WordPress 3.5 to 3.3.2 Cross-Site Scripting (XSS) (Issue 3) + WordPress 3.3.2 to 3.5 Cross-Site Scripting (XSS) (Issue 3) https://github.com/wpscanteam/wpscan/wiki/WordPress-3.5-Issues @@ -347,7 +347,7 @@ - WordPress 3.5 to 3.3.2 Cross-Site Scripting (XSS) (Issue 3) + WordPress 3.3.2 to 3.5 Cross-Site Scripting (XSS) (Issue 3) https://github.com/wpscanteam/wpscan/wiki/WordPress-3.5-Issues @@ -371,7 +371,7 @@ - WordPress 3.5 to 3.3.2 Cross-Site Scripting (XSS) (Issue 3) + WordPress 3.3.2 to 3.5 Cross-Site Scripting (XSS) (Issue 3) https://github.com/wpscanteam/wpscan/wiki/WordPress-3.5-Issues From 9d4481de0de186f182d278e4d24178edff88cae1 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Mon, 7 Oct 2013 22:14:05 +0200 Subject: [PATCH 4/4] Update wp_vulns.xml --- data/wp_vulns.xml | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/data/wp_vulns.xml b/data/wp_vulns.xml index 8d9cf491..ddb44cc2 100644 --- a/data/wp_vulns.xml +++ b/data/wp_vulns.xml @@ -249,7 +249,7 @@ UNKNOWN - WordPress 3.3.2 to 3.5 Cross-Site Scripting (XSS) (Issue 3) + WordPress 3.3.2 - 3.5 Cross-Site Scripting (XSS) (Issue 3) https://github.com/wpscanteam/wpscan/wiki/WordPress-3.5-Issues @@ -292,7 +292,7 @@ UNKNOWN - WordPress 3.3.2 to 3.5 Cross-Site Scripting (XSS) (Issue 3) + WordPress 3.3.2 - 3.5 Cross-Site Scripting (XSS) (Issue 3) https://github.com/wpscanteam/wpscan/wiki/WordPress-3.5-Issues @@ -316,7 +316,7 @@ - WordPress 3.3.2 to 3.5 Cross-Site Scripting (XSS) (Issue 3) + WordPress 3.3.2 - 3.5 Cross-Site Scripting (XSS) (Issue 3) https://github.com/wpscanteam/wpscan/wiki/WordPress-3.5-Issues @@ -347,7 +347,7 @@ - WordPress 3.3.2 to 3.5 Cross-Site Scripting (XSS) (Issue 3) + WordPress 3.3.2 - 3.5 Cross-Site Scripting (XSS) (Issue 3) https://github.com/wpscanteam/wpscan/wiki/WordPress-3.5-Issues @@ -371,7 +371,7 @@ - WordPress 3.3.2 to 3.5 Cross-Site Scripting (XSS) (Issue 3) + WordPress 3.3.2 - 3.5 Cross-Site Scripting (XSS) (Issue 3) https://github.com/wpscanteam/wpscan/wiki/WordPress-3.5-Issues