From db82b2584ce7342a816416bb6376b20ab4bd6430 Mon Sep 17 00:00:00 2001 From: Peter van der Laan Date: Sun, 13 Oct 2013 09:45:32 +0200 Subject: [PATCH] Update plugin_vulns.xml --- data/plugin_vulns.xml | 86 ++++++++++++++++++++++--------------------- 1 file changed, 45 insertions(+), 41 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 38f23238..e031715c 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -5,21 +5,23 @@ - Content Slide - Cross-Site Requst Forgery Vulnerability - CSRF + Content Slide 1.4.2 - Cross Site Requst Forgery Vulnerability 93871 + 2013-2708 52949 + CSRF - Simple Paypal Shopping Cart - Cross-Site Request Forgery Vulnerability + Simple Paypal Shopping Cart 3.5 - Cross-Site Request Forgery Vulnerability - 52963 93953 + 2013-2705 + 52963 CSRF 3.6 @@ -28,18 +30,19 @@ - WP-SendSMS - Setting Manipulation CSRF + WP-SendSMS 1.0 - Setting Manipulation CSRF - 53796 94209 + 53796 26124 CSRF - WP-SendSMS - wp-admin/admin.php Multiple Parameter XSS + WP-SendSMS 1.0 - wp-admin/admin.php Multiple Parameter XSS 94210 + 26124 XSS @@ -4261,6 +4264,8 @@ Extend 1.3.7 - Shell Upload vulnerability + 75638 + 2011-4106 17872 UPLOAD @@ -5098,7 +5103,7 @@ - Get Off Malicious Scripts Cross-Site Scripting Vulnerability + Get Off Malicious Scripts - Cross-Site Scripting Vulnerability 50030 @@ -5131,7 +5136,7 @@ - wp-explorer-gallery Arbitrary File Upload Vulnerability + wp-explorer-gallery - Arbitrary File Upload Vulnerability http://www.1337day.com/exploit/20251 @@ -5141,7 +5146,7 @@ - accordion Arbitrary File Upload Vulnerability + accordion - Arbitrary File Upload Vulnerability http://www.1337day.com/exploit/20254 @@ -5151,7 +5156,7 @@ - wp-catpro Arbitrary File Upload Vulnerability + wp-catpro - Arbitrary File Upload Vulnerability http://www.1337day.com/exploit/20256 @@ -5242,7 +5247,7 @@ - ForumConverter SQL Injection Vulnerability + ForumConverter - SQL Injection Vulnerability http://www.1337day.com/exploit/20275 @@ -5252,7 +5257,7 @@ - Newsletter SQL Injection Vulnerability + Newsletter - SQL Injection Vulnerability http://www.1337day.com/exploit/20287 @@ -5271,7 +5276,7 @@ - Cross-Site Scripting (XSS) Vulnerability in CommentLuv WordPress Plugin + CommentLuv - Cross Site Scripting Vulnerability https://www.htbridge.com/advisory/HTB23138 http://packetstormsecurity.com/files/120090/ @@ -5373,7 +5378,7 @@ - smart-flv jwplayer.swf XSS + smart-flv - jwplayer.swf XSS http://www.openwall.com/lists/oss-security/2013/02/24/7 http://packetstormsecurity.com/files/115100/ @@ -5397,7 +5402,6 @@ PHP Shell Plugin - https://github.com/wpscanteam/wpscan/issues/138 http://plugins.svn.wordpress.org/php-shell/trunk/shell.php @@ -5407,7 +5411,7 @@ - Marekkis Watermark Cross Site Scripting + Marekkis Watermark - Cross Site Scripting http://packetstormsecurity.com/files/120378/ @@ -5417,7 +5421,7 @@ - Responsive Logo Slideshow Cross Site Scripting + Responsive Logo Slideshow - Cross Site Scripting http://packetstormsecurity.com/files/120379/ @@ -5717,7 +5721,7 @@ - vkontakte-api XSS vulnerability + vkontakte-api - XSS vulnerability http://www.openwall.com/lists/oss-security/2013/03/11/1 2009-4168 @@ -5728,7 +5732,7 @@ - Terillion Reviews Cross Site Scripting + Terillion Reviews - Cross Site Scripting http://packetstormsecurity.com/files/120730/ @@ -5792,7 +5796,7 @@ - XSS vulnerability on WP-Banners-Lite + WP-Banners-Lite - XSS vulnerability http://seclists.org/fulldisclosure/2013/Mar/209 http://threatpost.com/en_us/blogs/xss-flaw-wordpress-plugin-allows-injection-malicious-code-032513 @@ -5828,7 +5832,7 @@ - ofc_upload_image.php Arbitrary File Upload Vulnerability + chikuncount - ofc_upload_image.php Arbitrary File Upload Vulnerability 24492 @@ -5838,7 +5842,7 @@ - ofc_upload_image.php Arbitrary File Upload Vulnerability + open-flash-chart-core - ofc_upload_image.php Arbitrary File Upload Vulnerability 24492 37903 @@ -5851,7 +5855,7 @@ - ofc_upload_image.php Arbitrary File Upload Vulnerability + spamtask - ofc_upload_image.php Arbitrary File Upload Vulnerability 24492 @@ -5861,7 +5865,7 @@ - ofc_upload_image.php Arbitrary File Upload Vulnerability + php-analytics - ofc_upload_image.php Arbitrary File Upload Vulnerability 24492 @@ -5871,7 +5875,7 @@ - ofc_upload_image.php Arbitrary File Upload Vulnerability + seo-spy-google - ofc_upload_image.php Arbitrary File Upload Vulnerability 24492 @@ -5881,7 +5885,7 @@ - ofc_upload_image.php Arbitrary File Upload Vulnerability + wp-seo-spy-google - ofc_upload_image.php Arbitrary File Upload Vulnerability 24492 @@ -5901,7 +5905,7 @@ - fbsurveypro XSS Vulnerability + fbsurveypro - XSS Vulnerability http://1337day.com/exploit/20623 @@ -5911,7 +5915,7 @@ - timelineoptinpro XSS Vulnerability + timelineoptinpro - XSS Vulnerability http://1337day.com/exploit/20620 @@ -5921,7 +5925,7 @@ - kioskprox XSS Vulnerability + kioskprox - XSS Vulnerability http://1337day.com/exploit/20624 @@ -5931,7 +5935,7 @@ - bigcontact SQLI + bigcontact - SQLI http://plugins.trac.wordpress.org/changeset/689798 @@ -5942,7 +5946,7 @@ - drawblog CSRF + drawblog - CSRF http://plugins.trac.wordpress.org/changeset/691178 @@ -5953,7 +5957,7 @@ - social-media-widget malicious code + social-media-widget - malicious code http://plugins.trac.wordpress.org/changeset?reponame=&old=691839%40social-media-widget%2Ftrunk&new=693941%40social-media-widget%2Ftrunk http://slashdot.org/submission/2592777/top-wordpress-widget-sold-off-turned-into-seo-spambot @@ -5966,7 +5970,7 @@ - facebook-members CSRF + facebook-members - CSRF 52962 2013-2703 @@ -5978,7 +5982,7 @@ - foursquare-checkins CSRF + foursquare-checkins - CSRF 53151 2013-2709 @@ -5990,7 +5994,7 @@ - formidable Pro Unspecified Vulnerabilities + formidable Pro - Unspecified Vulnerabilities 53121 @@ -6001,7 +6005,7 @@ - all-in-one-webmaster CSRF + all-in-one-webmaster - CSRF 52877 2013-2696 @@ -6043,7 +6047,7 @@ - syntaxhighlighter clipboard.swf XSS + syntaxhighlighter - clipboard.swf XSS 53235 @@ -6065,7 +6069,7 @@ - easy-adsense-lite CSRF + easy-adsense-lite - CSRF 52953 2013-2702 @@ -6086,7 +6090,7 @@ XSS - uk-cookie CSRF + uk-cookie - CSRF http://www.openwall.com/lists/oss-security/2013/06/06/10 94032 @@ -6098,7 +6102,7 @@ - wp-cleanfix Remote Command Execution, CSRF and XSS + wp-cleanfix - Remote Command Execution, CSRF and XSS https://github.com/wpscanteam/wpscan/issues/186 http://wordpress.org/support/topic/plugin-wp-cleanfix-remote-code-execution-warning