From dd38586eadc895c26244bd025f35ee974e863c5e Mon Sep 17 00:00:00 2001 From: Peter Date: Wed, 8 Jan 2014 20:57:52 +0100 Subject: [PATCH] Update plugin_vulns.xml --- data/plugin_vulns.xml | 58 ++++++++++++++++++++++++++++++++----------- 1 file changed, 43 insertions(+), 15 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 845b6d7e..ac68a8a8 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -2444,25 +2444,28 @@ - Download Monitor <= 3.3.6.1 - Cross Site Scripting + Download Monitor <= 3.3.6.1 - wp-admin/admin.php Multiple Parameter XSS - http://www.securityfocus.com/bid/61407 95613 2013-5098 2013-3262 53116 http://www.securityfocus.com/bid/61407 + http://xforce.iss.net/xforce/xfdb/85921 XSS 3.3.6.2 - Download Monitor <= 3.3.5.7 - Cross Site Scripting + Download Monitor <= 3.3.5.7 - index.php dlsearch Parameter XSS - http://www.reactionpenetrationtesting.co.uk/wordpress-download-monitor-xss.html + 85319 + 2012-4768 50511 + http://www.reactionpenetrationtesting.co.uk/wordpress-download-monitor-xss.html XSS + 3.3.5.9 Download Monitor <= 3.3.5.4 - Cross Site Scripting @@ -2471,6 +2474,15 @@ XSS + + Download Monitor 2.0.6 - wp-download_monitor/download.php id Parameter SQL Injection + + 44616 + 2008-2034 + 29876 + + SQLI + 2.0.8 @@ -6000,9 +6012,11 @@ - eShop Magic - "file" Arbitrary File Disclosure Vulnerability + eShop Magic 0.1 - eshop-magic/download.php file Parameter Traversal Arbitrary File Access + 86155 50933 + http://xforce.iss.net/xforce/xfdb/79222 LFI 0.2 @@ -6011,8 +6025,9 @@ - Pinterest "Pin It" Button Lite - Multiple Unspecified Vulnerabilities + Pinterest "Pin It" Button Lite 1.3.1 - Multiple Unspecified Vulnerabilities + 85956 50868 MULTI @@ -6068,8 +6083,9 @@ - Sexy Add Template - Cross-Site Request Forgery Vulnerability + Sexy Add Template 1.0 - PHP Code Execution CSRF + 85730 50709 CSRF @@ -6102,6 +6118,26 @@ + + WP-TopBar 4.02 - wp-topbar.php wptbbartext Parameter XSS + + 85659 + 50693 + 21393 + + XSS + 4.03 + + + WP-TopBar 4.02 - TopBar Message Manipulation CSRF + + 85660 + 50693 + 21393 + + + 4.03 + wp-topbar <= 3.04 - XSS in ZeroClipboard.swf @@ -6109,14 +6145,6 @@ XSS - - WP-TopBar - Cross-Site Request Forgery Vulnerability - - 50693 - - CSRF - 4.0.3 -