From e0ebd4773005a17070c38df8a5e532571dbc2c12 Mon Sep 17 00:00:00 2001 From: Peter Date: Sun, 18 May 2014 00:31:25 +0200 Subject: [PATCH] Update vuln db --- data/plugin_vulns.xml | 33 +++++++++++++++++++++++++++++++++ data/theme_vulns.xml | 9 +++++++++ 2 files changed, 42 insertions(+) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 1f7db67b..179f77cc 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -8090,6 +8090,15 @@ + + Formidable Forms 1.06.03 - ofc_upload_image.php Shell Upload Remote Code Execution + + 106985 + http://www.securityfocus.com/bid/67390 + http://packetstormsecurity.com/files/126583/ + + RCE + formidable Pro - Unspecified Vulnerabilities @@ -12637,4 +12646,28 @@ + + + Bonuspressx - ar_submit.php n Parameter XSS + + 106931 + http://packetstormsecurity.com/files/126595/ + + XSS + + + + + + Profile Builder 1.1.59 - front-end/wppb.recover.password.php Password Recovery Bypass + + 106986 + 58511 + http://www.securityfocus.com/bid/67331 + + AUTHBYPASS + 1.1.60 + + + diff --git a/data/theme_vulns.xml b/data/theme_vulns.xml index f426a3d0..1bfbd369 100644 --- a/data/theme_vulns.xml +++ b/data/theme_vulns.xml @@ -2792,6 +2792,15 @@ + + Echelon - media-upload.php Remote File Upload + + 106929 + http://www.securityfocus.com/bid/67080 + http://packetstormsecurity.com/files/126327/ + + UPLOAD + Echelon 2.4 - dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion