From e3796045eb35301c9b3e6a22fb2c25bef21038be Mon Sep 17 00:00:00 2001 From: Peter Date: Sun, 12 Jan 2014 23:22:53 +0100 Subject: [PATCH] Update plugin_vulns.xml --- data/plugin_vulns.xml | 89 ++++++++++++++++++++++++++++--------------- 1 file changed, 59 insertions(+), 30 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 3d25d363..555674f4 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -803,6 +803,13 @@ + + Smart Slideshow - upload.php Multiple File Extension Upload Arbitrary Code Execution + + 87373 + + UPLOAD + SWF Vulnerable to XSS Bundled in Many WordPress Plugins @@ -1709,8 +1716,10 @@ - SfBrowser Version 1.4.5 - Arbitrary File Upload Vulnerability + SFBrowser 1.4.5 - connectors/php/sfbrowser.php File Upload PHP Code Execution + 82845 + 49466 19054 UPLOAD @@ -1875,9 +1884,14 @@ - RBX Gallery 2.1 - Arbitrary File Upload + RBX Gallery 2.1 - uploader.php File Upload PHP Code Execution + 82796 + 2012-3575 + 49463 19019 + http://packetstormsecurity.com/files/113414/ + http://xforce.iss.net/xforce/xfdb/76170 UPLOAD @@ -3502,14 +3516,7 @@ - - - GRAND FlAGallery - Multiple Vulnerabilities - - 51100 - - MULTI - + SWF Vulnerable to XSS Bundled in Many WordPress Plugins @@ -3517,21 +3524,50 @@ XSS + + GRAND Flash Album Gallery 2.70- "s" Cross-Site Scripting Vulnerability + + 93714 + 2013-3261 + 53111 + + XSS + 2.72 + + + GRAND Flash Album Gallery 2.55 - "gid" SQL Injection Vulnerability + + 93087 + 53356 + + SQLI + 2.56 + + + GRAND Flash Album Gallery - Multiple Vulnerabilities + + 51100 + + MULTI + 2.17 + GRAND Flash Album Gallery 1.9.0 and 2.0.0 - Multiple Vulnerabilities + 51601 http://packetstormsecurity.com/files/117665/ http://www.waraxe.us/advisory-94.html - 51601 MULTI - GRAND Flash Album Gallery 0.55 - Multiple Vulnerabilities + GRAND Flash Album Gallery <= 1.71 - wp-admin/admin.php skin Parameter XSS - 16947 + 81923 + http://packetstormsecurity.com/files/112704/ - MULTI + XSS + 1.76 GRAND Flash Album Gallery <= 1.56 - XSS Vulnerability @@ -3541,29 +3577,22 @@ XSS - GRAND Flash Album Gallery <= 1.71 - XSS Vulnerability + GRAND Flash Album Gallery 0.55 - lib/hitcounter.php pid Parameter SQL Injection - http://packetstormsecurity.com/files/112704/ - - XSS - - - GRAND FlAGallery - "gid" SQL Injection Vulnerability - - 93087 - 53356 + 71072 + 43648 + 16947 SQLI - 2.56 - GRAND FlAGallery - "s" Cross-Site Scripting Vulnerability + GRAND Flash Album Gallery 0.55 - admin/news.php want2Read Parameter Traversal Arbitrary File Access - 53111 - 93714 + 71073 + 43648 + 16947 - XSS - 2.72 + UNKNOWN