From ec75b4418b378410faa497a774307fc8390b0552 Mon Sep 17 00:00:00 2001 From: Peter Date: Fri, 22 Nov 2013 11:56:47 +0100 Subject: [PATCH] Update plugin_vulns.xml --- data/plugin_vulns.xml | 30 +++++++++++++++++------------- 1 file changed, 17 insertions(+), 13 deletions(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 3f0f600b..847ed4cb 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -259,12 +259,13 @@ - Floating Social Media Links - Remote File Inclusion + Floating Social Media Links <= 1.4.2 - Remote File Inclusion 51346 http://ceriksen.com/2013/01/12/wordpress-floating-social-media-link-plugins-remote-file-inclusion/ RFI + 1.4.3 @@ -807,12 +808,13 @@ - SWF Vulnerable to XSS Bundled in Many WordPress Plugins + TinyMCE 3.5 - swfupload Cross-Site Scripting Vulnerability http://brindi.si/g/blog/vulnerable-swf-bundled-in-wordpress-plugins.html 51224 XSS + 3.6 @@ -4638,11 +4640,15 @@ UPLOAD - Category Grid View Gallery - CatGridPost.php ID Parameter XSS + Category Grid View Gallery 2.3.1 - CatGridPost.php ID Parameter XSS 94805 + 2013-4117 + 54035 + http://packetstormsecurity.com/files/122259/ XSS + 2.3.3 @@ -5856,18 +5862,14 @@ - wp-table-reloaded <= 1.9.3 - XSS in ZeroClipboard.swf + wp-table-reloaded <= 1.9.3 - zeroclipboard.swf id Parameter XSS - http://1337day.com/exploit/20396 - - XSS - - - wp-table-reloaded - cross-site scripting in SWF - - http://packetstormsecurity.com/files/119968/ + 89754 + 2013-1463 52027 + http://packetstormsecurity.com/files/119968/ http://seclists.org/bugtraq/2013/Feb/28 + http://www.securityfocus.com/bid/57664 XSS 1.9.4 @@ -7279,9 +7281,10 @@ - Stream Video Player - Setting Manipulation CSRF + Stream Video Player <= 1.4.0 - Setting Manipulation CSRF 94466 + 52954 CSRF @@ -8398,6 +8401,7 @@ 98978 2013-6342 + http://packetstormsecurity.com/files/124047/ XSS 4.0.2